Community
    • Login
    1. Home
    2. Popular
    Log in to post
    • All Time
    • Day
    • Week
    • Month
    • All Topics
    • New Topics
    • Watched Topics
    • Unreplied Topics
    • All categories
    • NppenjoyrN

      Advices to prevent further security vulnerabilities

      Watching Ignoring Scheduled Pinned Locked Moved Security
      4
      0 Votes
      4 Posts
      85 Views
      NppenjoyrN

      BTW:

      5.1-if your home internet speed is fast enough, setup your own web server to your pc under virtualbox(in case of web server software cve’s/rce’s). I or anyone can help with that. Dont forget to hardening server for security.

      IMO, this is BAD advice. To suggest to a non-security specialist who runs this as a hobby, that he should self-host, and try to keep up on all the security hardening, is asking him to get hacked even worse than the hack that already happened. He was literally paying a host to provide such services, and the professionals failed; he has now changed providers to a host who has better security procedures.

      Believe me it’s not that hard to setup a webserver or harden it, especially while backed by a strong community. The risks are different when hosting at home between hosting remotely. The hosting firm may be offered money to hijack, or an out-of-date hosting management software had rce was waiting to be abused.

    • A

      Tab bar tab width

      Watching Ignoring Scheduled Pinned Locked Moved Help wanted · · · – – – · · ·
      3
      0 Votes
      3 Posts
      43 Views
      A

      @PeterJones
      on the screenshot above Reduce option is already pressed though.
      Max tab label length truncates text, which is not the behavior i want to restore - i want the tabs with short names to not have this big gap at the end.

      That said, it seems that the “enable pin tab feature” was the culprit, as disabling it seems to have restored the desired tab size behavior.

      There still is some extra spacing before the close button though:

      2bb5dad1-4a85-4bd0-8df8-768e93562693-image.png
      629bde33-102c-4a09-a960-60ded9dcd809-image.png

    • S

      autoupdater and connection temp.sh

      Watching Ignoring Scheduled Pinned Locked Moved Security
      15
      0 Votes
      15 Posts
      9k Views
      xomxX

      Addendum to the points 2. & 3. above - even if you’re not to Reverse Engineering much, just follow the link and skip it to the ending “Indicators of compromise” part, where are some common markers that could help you decide whether or not your comp has been compromised:

      https://www.rapid7.com/blog/post/tr-chrysalis-backdoor-dive-into-lotus-blossoms-toolkit/

    • NppenjoyrN

      About recent security flaws

      Watching Ignoring Scheduled Pinned Locked Moved Help wanted · · · – – – · · ·
      2
      0 Votes
      2 Posts
      57 Views
      PeterJonesP

      @Nppenjoyr ,

      See this post

    • donhoD

      Notepad++ v8.9.1 Release

      Watching Ignoring Scheduled Pinned Locked Moved Announcements
      6
      6 Votes
      6 Posts
      3k Views
      PeterJonesP

      @A-T said in Notepad++ v8.9.1 Release:

      Bad that key is not certified with trusted sig.

      That just means that you haven’t marked it as trusted. GPG relies upon you to decide whether you trust a public key or not. If you don’t certify it as trusted, it will always say that it’s not signed with a trusted key, even though it confirms that it was signed with the key that it said it did.

    • Brian DickensB

      Notepad v8.8.2 32-bit installer: virus or malware detected

      Watching Ignoring Scheduled Pinned Locked Moved Security
      4
      0 Votes
      4 Posts
      8k Views
      PeterJonesP

      @Tavi ,

      As far as I can tell, they were unrelated. Scanners such as VirusTotal look at the executable itself, and last year were being triggered by the lack of signing and the self-signing of the executable.

      please confirm if this issue is related to the notepad++ hijack news dated 2nd Feb 2026?

      The issue you are referring to, as linked here and described in detail here specifically said,

      the compromise occured at the hosting provider level rather than through vulnerabilities in Notepad++ code itself.

      This was a website hack, and VirusTotal and other such AV scans do not detect website hacks, as far as I understand them.

    • Ilhan YumerI

      notepad-plus-plus.org should be added to the HSTS preload list

      Watching Ignoring Scheduled Pinned Locked Moved Security hsts domain security
      1
      0 Votes
      1 Posts
      18 Views
      No one has replied
    • donhoD

      WHEN GOOGLE IS POSSESSED BY PROFIT

      Watching Ignoring Scheduled Pinned Locked Moved Announcements
      23
      6 Votes
      23 Posts
      20k Views
      donhoD

      It seems that malicious ads (promoting a fake Notepad++ website) have returned on the Google search page.
      Below is the email I received this morning:

      Hi Don
      I am a long-time user and admirer of Notepad++. I am based in Australia.

      Today, I went to download a copy of Notepad++ to a new machine. When I searched for “Notepad++” in Google, the first link which came up appears to be a FAKE website located in China:

      https://www[.]notepadplus[.]com[.]cn/en/

      I thought I should let you know, in case this is some kind of hacking attempt.

      Any follow up questions, just let me know.

      Kind regards

      If anyone here has encountered these malicious ads, please use the following link to report them to Google:
      https://support.google.com/ads/troubleshooter/4578507?visit_id=639056285883908601-3926234762&rd=1