logoalt Hacker News

leduyquang753today at 9:02 AM1 replyview on HN

That recent Notepad++ incident was a supply chain attack, not a vulnerability in the original program.


Replies

SPICLK2today at 9:04 AM

Strictly, no. But it was a vulnerability in the design of Notepad++, key elements here being the featureset that requires frequent updates and the lack of integrity checks during the upgrade process.

This has prompted me to move on from Notepad++ - it's sad, because I've used it for many years, but this is too much.

show 1 reply