Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
evacide
evacide
@evacide@hachyderm.io  路  activity timestamp 5 days ago

Notepad++ publishes a blog post saying they caught a probably-Chinese state actor hijacking their product in an attack against highly-selective targets that began last June: https://notepad-plus-plus.org/news/hijacked-incident-info-update/

Notepad++ Hijacked by State-Sponsored Hackers | Notepad++

  • Copy link
  • Flag this post
  • Block
John Carlsen 馃嚭馃嚫馃嚦馃嚤馃嚜馃嚭
John Carlsen 馃嚭馃嚫馃嚦馃嚤馃嚜馃嚭
@johnlogic@sfba.social replied  路  activity timestamp 4 days ago

@evacide

In the pages linked article at
https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/ the mention of "undocumented system calls" in Microsoft Windows should serve as a warning not to use Windows at all, as it clearly can't be trusted. The cited name of one of those calls ("NtQuerySystemInformation") amused me by evoking memories of using Windows NT circa 1996.

Apparently Microsoft hasn't been adequately compelled to improve its products in the last 30 years.

Rapid7

The Chrysalis Backdoor: A Deep Dive into Lotus Blossom鈥檚 toolkit

Rapid7 Labs, together with the Rapid7 MDR team, has uncovered a sophisticated campaign attributed to the Chinese APT group Lotus Blossom.
  • Copy link
  • Flag this comment
  • Block
John Carlsen 馃嚭馃嚫馃嚦馃嚤馃嚜馃嚭
John Carlsen 馃嚭馃嚫馃嚦馃嚤馃嚜馃嚭
@johnlogic@sfba.social replied  路  activity timestamp 4 days ago

@evacide

I learned a new term of art: "indicator of compromise" (IoC).

(Computer forensics is outside my area of expertise.)

https://en.wikipedia.org/wiki/Indicator_of_compromise

Indicator of compromise - Wikipedia

  • Copy link
  • Flag this comment
  • Block
Greg
Greg
@Greg2935@mastodon.social replied  路  activity timestamp 5 days ago

@evacide this sort of thing has been on the rise for years, the hosting company should be publicized to reduce the incentive to side with bad actors

  • Copy link
  • Flag this comment
  • Block
James Knaus
James Knaus
@sudo_asap@mastodon.social replied  路  activity timestamp 5 days ago

@evacide I love notepad++ it's my go to ide

  • Copy link
  • Flag this comment
  • Block
Eeyore_Syndrome
Eeyore_Syndrome
@Eeyore_Syndrome@hachyderm.io replied  路  activity timestamp 5 days ago

@evacide

I highly reccomend:
#KDE #Kate

https://apps.kde.org/kate/
https://kate-editor.org/

Even has a windows version.

  • Copy link
  • Flag this comment
  • Block
Bodling
Bodling
@Bodling@deacon.social replied  路  activity timestamp 5 days ago

@evacide What we need to do comes at the end:

"I deeply apologize to all users affected by this hijacking. I recommand downloading v8.9.1 (which includes the relevant security enhancement) and running the installer to update your Notepad++ manually."

  • Copy link
  • Flag this comment
  • Block
slash
slash
@agreeable_landfall@mastodon.social replied  路  activity timestamp 5 days ago

@evacide It's ironic that my company blocks anything with that domain in it. Including the SMB share we're supposed to download it from...

In this case, I'm a sysadmin and won't be able to read and react to this because IT has it blocked.

These are the same people who allow access to the Daily Mail, but not The Guardian...

  • Copy link
  • Flag this comment
  • Block
Dan Schnau
Dan Schnau
@danschnau@mastodon.social replied  路  activity timestamp 5 days ago

@evacide I vaguely remember reading about an attack like this on notepad++ many years ago. What a pain to be the target of this stuff!

  • Copy link
  • Flag this comment
  • Block
DB Schwein
DB Schwein
@deirdrebeth@mas.to replied  路  activity timestamp 5 days ago

@evacide

@marfisk FYI

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About 路 Code of conduct 路 Privacy 路 Users 路 Instances
Bonfire social 路 1.0.2-alpha.7 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct