China Cybersecurity

Notepad++ Update Hijacked by Chinese Hackers Months Long Compromise

During a cyberattack between June and December 2025, hackers associated with the Chinese government compromised the open-source text editor Notepad++. Exploiting a bug in the software and a shared hosting server, attackers delivered malicious updates to targeted users, including those in government, telecom, and critical infrastructure sectors. This sophisticated espionage campaign, attributed to the Lotus Blossom group, allowed hackers to gain hands-on access to victim systems until the vulnerability was patched in November. The developer has since apologized and urged users to update to the latest version.

Read More

Trump’s Cyber Security Head Uploads Sensitive Materials to ChatGPT

A recent report reveals that Madhu Gottumukkala, the head of the Cybersecurity and Infrastructure Security Agency, uploaded “sensitive” contracting materials to a public version of ChatGPT, triggering an internal review. The documents, marked “for official use only,” were not classified but were considered sensitive and should not have been released publicly, which triggered automated alerts. Despite Gottumukkala having special permission to use ChatGPT, the incident prompted a review by top DHS officials to assess potential harm, with the results still unknown. This event occurred amid the widespread adoption of AI in the workplace, highlighting the increasing need for careful handling of sensitive information.

Read More

China Orders Firms to Stop Using US, Israeli Cybersecurity Software

Beijing tells Chinese firms to stop using US and Israeli cybersecurity software, sources say. Well, this is a pretty significant move, isn’t it? It seems Beijing has instructed its domestic companies to immediately ditch cybersecurity software from about a dozen U.S. and Israeli firms. The rationale? National security. They’re worried about the potential for these tools to collect and transmit sensitive data back to those countries. Think of it as a preemptive strike against potential vulnerabilities, a move to safeguard their digital infrastructure.

This directive really underscores China’s commitment to technological self-reliance, and it’s happening at a rapid pace, especially with all the tech tensions brewing between the U.S.… Continue reading