North America
Notepad++
The popular open-source code editor Notepad++ was targeted by state-sponsored attackers in a supply-chain attack, putting the integrity of software updates at risk.
Notepad++ is a free, open-source text and source code editor for Microsoft Windows. The project confirmed that attackers quietly hijacked its software update infrastructure in a targeted campaign, intercepting and redirecting update traffic intended for notepad-plus-plus.org. This allowed malicious binaries to be delivered to select users over an extended period.
The attack unfolded over a six-month period, from June to December 2025, primarily affecting users running older versions of the WinGUp updater.
How it could affect your business
This incident highlights how trusted software distribution mechanisms can become high-risk attack surfaces when infrastructure or validation controls fail. Reducing exposure requires a layered defensive approach that extends beyond patch management to include visibility, control and preparedness across the software update lifecycle.
