• AceBonobo@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 day ago

    You might have version 8.8.1 or lower, however it might have tried to order update got the vulnerable package instead and then remained on the older version. I think even if you have the older version that’s not a sign that you weren’t compromised.

    • pez@piefed.blahaj.zone
      link
      fedilink
      English
      arrow-up
      1
      ·
      20 hours ago

      Fair point. I was assuming the malicious payload would come along with an update on order to hide, but it’s also possible that the malicious payload was delivered without any update to notepad++.

      I’ve not seen any IOCs published have you?

      • AceBonobo@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        I’m not sure what you mean. The article states there were remote hands on keyboard noticed in multiple companies. That’s how the vulnerability was discovered.