submitted 8 months ago* (last edited 8 months ago) by to c/technology@lemmy.world
you are viewing a single comment's thread
view the rest of the comments
[–] 187 points 8 months ago* (1 child)

tl;dr A network operator can perform a MitM attack on the built-in updater's call-out checking for updates by faking the Notepad++ update website, telling it a new version is available at and then downloading and running the malware

It requires a malicious network operator, or preexisting malware on the host.

  • source
  • hideshow 2 child comments