
State-Sponsored Actors Hijacked Notepad++ Update to Redirect Users to Malicious Servers
The developer of Notepad++ has confirmed that a targeted attack by a likely Chinese state-sponsored threat actor compromised the project’s former shared hosting infrastructure between June and December 2025. The breach allowed attackers to intercept and selectively redirect update traffic to malicious servers, exploiting a weakness in how the software validated update packages before the […] The post State-Sponsored Actors Hijacked Notepad++ Update to Redirect Users to Malicious Servers appeared first on Cyber Security News.