Notepad++ Strengthens Update Security After Cyberattack by Lotus Blossom
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
Notepad++ has made significant strides in securing its update process, particularly with the release of version 8.9.2. This version implements verification of signed XML from notepad-plus-plus.org, alongside the signed installer verification introduced in version 8.8.9. These enhancements are part of a broader effort to ensure that the update process is robust and claims to be ‘effectively unexploitable.’
The impetus for these changes stems from a cyberattack attributed to the Lotus Blossom group, which is linked to state-sponsored cybercriminals from China. This attack involved redirecting update traffic to a malicious site that served malware disguised as legitimate updates. Following this incident, Notepad++ released a ‘hardened’ version on December 9, 2025, and subsequently removed the use of self-signed certificates on December 27.
The recent updates also include additional hardening measures for the auto-updater, WinGUp. Notably, the dependency on libcurl.dll has been eliminated to mitigate DLL side-loading risks, and plugin management execution is now restricted to programs signed with the same certificate as WinGUp. Furthermore, two unsecured cURL SSL options have been removed to enhance security.
This situation underscores the critical need for software developers to prioritize security in their update processes. Users and organizations should be aware of the risks associated with software updates and ensure they are using the latest versions to protect against potential vulnerabilities.
For everyday users, the ability to exclude the auto-updater during installation or deploy the MSI package with specific commands provides flexibility in managing their installations. However, keeping the software updated is crucial to safeguard against any future threats.
Why This Matters for Your Security
The enhancements to Notepad++’s update process reflect a growing recognition of the importance of software integrity in cybersecurity. As cyber threats evolve, the need for robust verification mechanisms becomes paramount.
Organizations should take note of these developments and consider implementing similar verification processes for their own software updates. Regularly updating software and monitoring for any unusual activity can help mitigate risks associated with cyberattacks.
Key Takeaways
- Update to Notepad++ version 8.9.2 to benefit from the enhanced security features.
- Consider excluding the auto-updater during installation if you prefer manual updates.
- Monitor official Notepad++ communications for future security updates and advisories.
- Evaluate your organization’s software update processes to ensure they include robust verification mechanisms.
- Educate users about the risks of downloading software from unofficial sources.
Key Terms & Concepts
- Lotus Blossom: In this article, Lotus Blossom refers to a Chinese government-linked espionage group responsible for a cyberattack on Notepad++.
- DLL side-loading: DLL side-loading is a technique used by attackers to exploit vulnerabilities by loading malicious DLL files instead of legitimate ones.
- WinGUp: WinGUp is the auto-updater for Notepad++, which has undergone security enhancements to protect against potential threats.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.