Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Notepad++ boosts update security with ‘double-lock’ mechanism
    Cybersecurity

    Notepad++ boosts update security with ‘double-lock’ mechanism

    adminBy adminFebruary 17, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Notepad++ boosts update security with ‘double-lock’ mechanism
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Notepad++ boosts update security with ‘double-lock’ mechanism

    Notepad++ has adopted a “double-lock” design for its update mechanism to address recently exploited security gaps that resulted in a supply-chain compromise.

    The new mechanism landed in Notepad++ version 8.9.2, announced yesterday, although work on it began in version 8.8.9 with implementing the verification of the signed installer from GitHub.

    The second part of the double-lock system is checking the signed XML from the notepad-plus-plus.org domain. In practice, this means that the XML file returned from the update service is digitally signed (XMLDSig).

    Wiz

    The combination of the two verification mechanisms adds to a more robust “and effectively unexploitable” update process, says the team behind the massively popular open-source text and source code editor.

    Additional security-oriented changes applied to the auto-updater include:

    • Removal of libcurl.dll to eliminate DLL side-loading risk
    • Removal of two unsecured cURL SSL options: CURLSSLOPT_ALLOW_BEAST and CURLSSLOPT_NO_REVOKE
    • Restriction of plugin management execution to programs signed with the same certificate as WinGUp

    The new announcement also notes that users can exclude the auto-updater during UI installation or deploy the MSI package with: msiexec /i npp.8.9.2.Installer.x64.msi NOUPDATER=1

    Vulnerable update model (left) and new, secure model (right)
    Vulnerable update model (left) and new, secure model (right)
    Source: Notepad++

    Earlier this month, Notepad++  and Rapid7 researchers disclosed that the update infrastructure was compromised in a six-month-long campaign attributed to Lotus Blossom, a threat group linked to China.

    Starting in June 2025, the bad actor compromised the hosting provider that ran the Notepad++ updater and selectively redirected update requests from specific users to malicious servers.

    The attacks exploited weak update verification controls used in older versions of the software, and continued until their discovery on December 2, 2025.

    Rapid7’s analysis revealed that the Chinese hackers used a custom backdoor called “Chrysalis” as part of the attack chain.

    Apart from the newly introduced security measures, the project immediately switched to a different hosting provider, rotated credentials, and fixed flaws exploited in the discovered attacks.

    The recommended action for all Notepad++ users is to upgrade to version 8.9.2, and ensure that installers are always downloaded from the official domain, notepad-plus-plus.org.


    tines

    Modern IT infrastructure moves faster than manual workflows can handle.

    In this new Tines guide, learn how your team can reduce hidden manual delays, improve reliability through automated response, and build and scale intelligent workflows on top of tools you already use.

    boosts doublelock Mechanism Notepad Security update
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleTikTok launches AI-powered ad options for entertainment marketers
    Next Article I turned off these Gboard features, and typing feels infinitely better now
    admin
    • Website

    Related Posts

    Russian Ransomware Operator Pleads Guilty in US

    March 5, 2026

    Pixel Weather app update brings new redesigned icons

    March 5, 2026

    Cisco Drops 48 New Firewall Vulnerabilities, 2 Critical

    March 5, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Russian Ransomware Operator Pleads Guilty in US

    March 5, 2026

    Pixel Weather app update brings new redesigned icons

    March 5, 2026

    Data center new builds diminish even as demand rises

    March 5, 2026

    Cisco Drops 48 New Firewall Vulnerabilities, 2 Critical

    March 5, 2026
    Categories
    • Blogging (33)
    • Cybersecurity (623)
    • Privacy & Online Earning (92)
    • SEO & Digital Marketing (395)
    • Tech Tools & Mobile / Apps (760)
    • WiFi / Internet & Networking (112)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Russian Ransomware Operator Pleads Guilty in US

    March 5, 2026

    Pixel Weather app update brings new redesigned icons

    March 5, 2026

    Data center new builds diminish even as demand rises

    March 5, 2026
    Most Popular
    • Russian Ransomware Operator Pleads Guilty in US
    • Pixel Weather app update brings new redesigned icons
    • Data center new builds diminish even as demand rises
    • Cisco Drops 48 New Firewall Vulnerabilities, 2 Critical
    • What SMEC’s Data Reveals About AI Max Performance
    • This Ultra phone first to use Sony’s new 200MP camera sensor
    • Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities
    • Yep, Amazon Is Down | Lifehacker
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.