▲ 16 ▼ Notepad++ updater installed malware (www.heise.de) submitted 8 months ago by floofloof@lemmy.ca to c/cybersecurity@sh.itjust.works 2 comments fedilink hide all child comments
[–] lurch@sh.itjust.works 18 points 8 months ago (1 child) Headline seems intentionally vague. The updater was vulnerable to a download man-in-the-middle attack, because it used a weak certificate. permalink fedilink source hideshow 2 child comments replies: [–] smeg@infosec.pub 12 points 8 months ago Which requires a malicious network operator or some other kind of DNS poisoning. Not exactly a radical exploit permalink fedilink source parent
[–] smeg@infosec.pub 12 points 8 months ago Which requires a malicious network operator or some other kind of DNS poisoning. Not exactly a radical exploit permalink fedilink source parent