Lemdro.id
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Pierre-Yves Lapersonne@programming.devM to Opensource@programming.dev · 19 days ago

Notepad++ hijacked by state-sponsored hackers

notepad-plus-plus.org

external-link
message-square
5
link
fedilink
  • cross-posted to:
  • foss@beehaw.org
  • opensource@lemmy.ml
  • homeassistant@lemmit.online
  • cybersecurity@infosec.pub
  • technology@lemmy.ml
  • pcmasterrace@lemmit.online
  • technik@feddit.org
  • technology@lemmy.world
  • notepadplusplus@programming.dev
20
external-link

Notepad++ hijacked by state-sponsored hackers

notepad-plus-plus.org

Pierre-Yves Lapersonne@programming.devM to Opensource@programming.dev · 19 days ago
message-square
5
link
fedilink
  • cross-posted to:
  • foss@beehaw.org
  • opensource@lemmy.ml
  • homeassistant@lemmit.online
  • cybersecurity@infosec.pub
  • technology@lemmy.ml
  • pcmasterrace@lemmit.online
  • technik@feddit.org
  • technology@lemmy.world
  • notepadplusplus@programming.dev
Notepad++ Hijacked by State-Sponsored Hackers | Notepad++
notepad-plus-plus.org
external-link
alert-triangle
You must log in or register to comment.
  • Wurzelfurz@feddit.org
    link
    fedilink
    English
    arrow-up
    4
    ·
    18 days ago

    He added a link to a deep dive for the backdoor used in the attack.

    https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/

  • artyom@piefed.social
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    18 days ago

    I’m so confused.

    1. It doesn’t say anything about “state-sponsored attackers” outside of the headline? What state? Why?
    2. Why is a Notepad app connecting to any servers or have credentials at all?
    • voracitude@lemmy.world
      link
      fedilink
      arrow-up
      5
      arrow-down
      1
      ·
      edit-2
      2 days ago

      deleted by creator

    • Dem Bosain@midwest.social
      link
      fedilink
      English
      arrow-up
      0
      ·
      18 days ago

      It wasn’t specifically notepad++ code, but a custom-written updater. That’s why it was connecting to the internet.

      • village604@adultswim.fan
        link
        fedilink
        English
        arrow-up
        2
        ·
        18 days ago

        I mean, it is n++ code because the updater is part of the code base. They just didn’t have the connection to the update server hardened.

        This was patched in like December, though.

  • Calfpupa [she/her]@lemmy.ml
    link
    fedilink
    English
    arrow-up
    1
    ·
    18 days ago

    It used to be that being a ML (Malicious Linguist) in someones garage was the rage, now we got “Hackers with Chinese characteristics” smh

Opensource@programming.dev

opensource@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !opensource@programming.dev

A community for discussion about open source software! Ask questions, share knowledge, share news, or post interesting stuff related to it!

Credits

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

⠀


Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 141 users / day
  • 798 users / week
  • 2.02K users / month
  • 5.66K users / 6 months
  • 9 local subscribers
  • 5.6K subscribers
  • 1.44K Posts
  • 5.09K Comments
  • Modlog
  • mods:
  • Pierre-Yves Lapersonne@programming.dev
  • UI: 0.19.11
  • BE: 0.19.12
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org