Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • Portable water filter provides safe drinking water from any source
    • MAGA Is Increasingly Convinced the Trump Assassination Attempt Was Staged
    • NCAA seeks faster trial over DraftKings disputed March Madness branding case
    • AI Trusted Less Than Social Media and Airlines, With Grok Placing Last, Survey Says
    • Extragalactic Archaeology tells the ‘life story’ of a whole galaxy
    • Swedish semiconductor startup AlixLabs closes €15 million Series A to scale atomic-level etching technology
    • Republican Mutiny Sinks Trump’s Push to Extend Warrantless Surveillance
    • Yocha Dehe slams Vallejo Council over rushed casino deal approval process
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Saturday, April 18
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Notepad++ users take note: It’s time to check if you’re hacked
    News

    Notepad++ users take note: It’s time to check if you’re hacked

    Editor Times FeaturedBy Editor Times FeaturedFebruary 2, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link


    Beaumont wrote:

    If you happen to can intercept and alter this visitors, you may redirect the obtain to any location it seems by altering the URL within the property.

    This visitors is meant to be over HTTPS, nonetheless it seems chances are you’ll be [able] to tamper with the visitors in the event you sit on the ISP degree and TLS intercept. In earlier variations of Notepad++, the visitors was simply over HTTP.

    The downloads themselves are signed—nonetheless some earlier variations of Notepad++ used a self signed root cert, which is on Github. With 8.8.7, the prior launch, this was reverted to GlobalSign. Successfully, there’s a state of affairs the place the obtain isn’t robustly checked for tampering.

    As a result of visitors to notepad-plus-plus.org is pretty uncommon, it might be potential to sit down contained in the ISP chain and redirect to a special obtain. To do that at any type of scale requires numerous sources.

    Beaumont revealed his working idea in December, two months to the day previous to Monday’s advisory by Notepad++. Mixed with the small print from Notepad++, it’s now clear the speculation was spot on.

    Beaumont additionally warned that search engines like google and yahoo are so “rammed full” of ads pushing trojanized variations of Notepad++ that many customers are unwittingly operating them inside their networks. A rash of malicious Notepad++ extensions solely compound the danger.

    He suggested that every one customers guarantee they’re operating the official model 8.8.8 or greater put in manually from notepad-plus-plus.org. Since he penned that recommendation, Notepad++ builders have urged all customers to make sure they’re operating 8.9.1 or greater.

    Bigger organizations that handle Notepad++ and replace it, he mentioned, ought to take into account blocking notepad-plus-plus.org or block the gup.exe course of from having Web entry. “You might also wish to block web entry from the notepad++.exe course of, except you might have sturdy monitoring for extensions,” he added, however cautioned “for many organisations, that is very a lot overkill and never sensible.”

    Screenshot

    Notepad++ has lengthy attracted a big and constant person base as a result of it gives features that aren’t obtainable from the official Home windows textual content editor Notepad. Latest strikes by Microsoft to integrate Copilot AI into Notepad have pushed additional curiosity within the various editor. Alas, like so many different open supply tasks, funding for Notepad++ is dwarfed by the dependence the Web locations on it. The weaknesses that made the six-month compromise potential may simply have been caught and stuck had extra sources been obtainable.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    NCAA seeks faster trial over DraftKings disputed March Madness branding case

    April 18, 2026

    Yocha Dehe slams Vallejo Council over rushed casino deal approval process

    April 18, 2026

    CFTC’s one-man show gets awkward on the Hill as lawmakers hammer Selig on sports bets, staffing gaps and corruption claims

    April 17, 2026

    Maryland session ends leaving sweepstakes gaming bills stalled once again as SGLA celebrates

    April 17, 2026

    New York lawsuit says Stake and Coinbase targeted child gambler for years

    April 17, 2026

    Recent advances push Big Tech closer to the Q-Day danger zone

    April 17, 2026

    Comments are closed.

    Editors Picks

    Portable water filter provides safe drinking water from any source

    April 18, 2026

    MAGA Is Increasingly Convinced the Trump Assassination Attempt Was Staged

    April 18, 2026

    NCAA seeks faster trial over DraftKings disputed March Madness branding case

    April 18, 2026

    AI Trusted Less Than Social Media and Airlines, With Grok Placing Last, Survey Says

    April 18, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Google Pixel 10A vs. Pixel 10, 10 Pro, 10 Pro XL: How the Cheaper Pixel Matches Up

    February 18, 2026

    AI Trusted Less Than Social Media and Airlines, With Grok Placing Last, Survey Says

    April 18, 2026

    Enhance your AP automation workflows

    May 22, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.