3 ms·
So what mitigations should the end user be doing? How do we know if anything compromised?
by daemonhunter 8mo ago
So what mitigations should the end user be doing? How do we know if anything compromised?
- avereveard 8mo agoRight the writeup doesn't mention when it started and what versions are affected
- hug 8mo ago> Based on both assessment, I estimate the overall compromise period spanned from June through December 2, 2025, when all attacker access was definitively terminated. FTA.
- freitasm 8mo agoThe writeup says it right there: "The security exper’s analysis indicates the attack ceased on November 10, 2025, while the hosting provider’s statement shows potential attacker access until December 2, 2025. Based on both assessment, I estimate the overall compromise period spanned from June through December 2, 2025, when all attacker access was definitively terminated."
- avazhi 8mo agoYeah, that refers to the MITM attack on the update server. We have no fucking clue what they actually did while they were in the middle - whatever exploit code was running may very well be running right now on compromised machines. Nobody knows what the compromised exes actually did. Thanks for your nonanswer, though. It was about as unhelpful and unspecific as the original blogpost for this.
- kijin 8mo agoDownload the latest version and install that, instead of using the auto update feature of an old version that might not properly check signatures. As for whether anything else has been compromised, it depends on whether you were targeted. And the payload might have been tailored to each target, so there's no way to know unless you have access to the exact binary. Unfortunately, binaries downloaded through the auto update feature tend not to linger in your Downloads folder.
- username223 8mo agoDisable auto-updates, just like you should with every piece of software on your machine. This was the result of letting other people silently replace your programs. Don't allow that.
- bibimsz 8mo agothat's why I still run Windows XP. Automatic updates are dangerous!
- username223 8mo agoHow's Windows 11 treating you, my man?
- pxc 8mo agoCentralized automatic updates, like those of a Linux distribution or Microsoft's Windows Updates, involve giving permission to way fewer parties permission to download and run (unsigned, in the case of Notepad++ this time) code on your machine with high privileges. And for more modern software distribution mechanisms (e.g., Nix, Guix, Flatpak), centralized package updates may not actually run any vendor code with high privileges at all. The norm for proprietary software updates on Windows is indeed a free-for-all of every publisher downloading and running code with admin rights, and it is indeed a terrible way to operate. Avoiding that kind of madness doesn't necessarily mean running lots of old, vulnerable software.