[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / r / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: 1760954933561420.jpg (91 KB, 1200x660)
91 KB
91 KB JPG
https://cybernews.com/security/hackers-exploit-vulnerability-in-notepad-plus-plus-updater/
>Security researcher Kevin Beaumont previously reported that at least three organizations in East Asia had been compromised via a common attack vector – Notepad++ installations.
>Don Ho, the creator and maintainer of Notepad++, acknowledged the vulnerability and released an updated version of Notepad++.
>“According to the investigation, traffic from WinGUp (the Notepad++ updater) was occasionally redirected to malicious servers, resulting in the download of compromised executables,” the Notepad++ advisory reads.
>The maintainer identified a weakness in the updater's validation of the integrity and authenticity of downloaded update files.
>Attackers, who can intercept network traffic between the updater client and the Notepad++ update server, were likely exploiting this flaw to trick the updater into downloading and running malicious executables, instead of legitimate updates.
>Beaumont explained that Notepad++’s updater sends the current app version in use to the update service, which in turn provides an XML file containing a download URL for the update. It is likely that hackers were able to redirect the traffic to a malicious location by changing the URL in the file.
>Earlier app versions used self-signed root certificates, and anti-tampering protection might not have been robust enough.
>>
>>107512215
i don't get it, how did the attackers "intercept network traffic between the updater client and the Notepad++ update server"? isn't it going over TLS?
>>
>>107512215
>starts virtue signaling
>software shits the bed
many such cases
>>
File: 1736973104061.png (39 KB, 675x576)
39 KB
39 KB PNG
>>107512296
you expect a nonbinary leftard vibecoder to implement basic security measures?



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.