{"id":10740,"date":"2026-02-18T10:03:40","date_gmt":"2026-02-18T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/02\/18\/notepad-v8-9-2-released-with-double-lock-update-mechanism-following-recent-hack\/"},"modified":"2026-02-18T10:03:40","modified_gmt":"2026-02-18T10:03:40","slug":"notepad-v8-9-2-released-with-double-lock-update-mechanism-following-recent-hack","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/02\/18\/notepad-v8-9-2-released-with-double-lock-update-mechanism-following-recent-hack\/","title":{"rendered":"Notepad++ v8.9.2 Released with \u201cDouble-Lock\u201d Update Mechanism Following Recent Hack"},"content":{"rendered":"<p>    Notepad++ v8.9.2 Released with \u201cDouble-Lock\u201d Update Mechanism Following Recent Hack<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The widely used open-source text and code editor has released version\u00a0v8.9.2, introducing a major security enhancement known as the\u00a0\u201cDouble-Lock\u201d update mechanism.<\/p>\n<p>This update addresses vulnerabilities that were exploited in a recent state-sponsored attack\u00a0targeting the application\u2019s update infrastructure.<\/p>\n<p>Last month, <a href=\"https:\/\/cybersecuritynews.com\/notepad-hijacked\/\" type=\"post\" id=\"141209\" target=\"_blank\" rel=\"noreferrer noopener\">Notepad++\u2019s official site confirmed that attackers had successfully hijacked<\/a> its update channel, allowing the distribution of a malicious update.<\/p>\n<p>Following the incident, the development team promised to fortify the update verification process. That promise has now been fulfilled with the v8.9.2 release.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-strengthening-the-update-process\"><strong>Strengthening the Update Process<\/strong><\/h2>\n<p>The <a href=\"https:\/\/notepad-plus-plus.org\/downloads\/v8.9.2\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">latest release introduces<\/a>\u00a0XMLDSig (XML Digital Signature)\u00a0verification for update files.<\/p>\n<p>The\u00a0XML returned by Notepad++\u2019s update server is now cryptographically signed, and both the signature and certificate will be verified before any updates are applied.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi5FtnKTVbMYBu-QiM5khv0cbpNImF5QVK-3RCP4j1cW80tGzHVFY2ouj1pr1HXOg8ieONx9qAKQe8N6j3ZF-6AO1KJZ24U3kfPKflRdGysyTkxMOUn5j_emw3FED93V45oSYag9HMs4EMUp04HVN4idcCvvZZzszZ6fa4GXM0OuggN05RLKWG_-XdFLr8\/s1600\/Screenshot%25202026-02-18%2520120439%2520%25281%2529.webp?ssl=1\" alt=\"Fixed in Notepad++ v8.9.2 (source : notepad-plus-plus.org)\"><figcaption class=\"wp-element-caption\">Fixed in Notepad++ v8.9.2 (source : notepad-plus-plus.org)<\/figcaption><\/figure>\n<p>This means that, starting with v8.9.2, all future updates will only be accepted if they are verified against trusted Notepad++ certificates.<\/p>\n<p>In addition to this measure, Notepad++ now performs two independent verifications forming what the developers describe as a\u00a0\u201cDouble-Lock\u201d update system:<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Verification Layer<\/th>\n<th>Source<\/th>\n<th>Version<\/th>\n<th>Purpose<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>XML Signature Verification<\/strong><\/td>\n<td>Notepad++ official site<\/td>\n<td>v8.9.2<\/td>\n<td>Verifies signed update metadata (XML) to prevent tampering or spoofed update info.<\/td>\n<\/tr>\n<tr>\n<td><strong>Installer Signature Verification<\/strong><\/td>\n<td>GitHub<\/td>\n<td>v8.8.9<\/td>\n<td>Validates installer digital signature to block modified or malicious binaries.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Together, these measures create a resilient security model that prevents malicious interception or tampering of update files. The development team notes that this design effectively makes the update process \u201crobust and unexploitable.\u201d<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-wingup-auto-updater-enhancements\"><strong>WinGUp Auto-Updater Enhancements<\/strong><\/h2>\n<p>The\u00a0WinGUp auto-updater, which manages update downloads and installations, has also undergone a significant security overhaul.<\/p>\n<p><strong>Key improvements include:<\/strong><\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>Category<\/th>\n<th>Improvement<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><strong>Update Security<\/strong><\/td>\n<td>XMLDSig signing<\/td>\n<td>Update XML files from Notepad++ server are digitally signed for integrity verification.<\/td>\n<\/tr>\n<tr>\n<td><strong>Double Verification<\/strong><\/td>\n<td>Dual update validation<\/td>\n<td>Signed XML (official site) + signed installer from GitHub.<\/td>\n<\/tr>\n<tr>\n<td><strong>Certificate Enforcement<\/strong><\/td>\n<td>Strict signature checks<\/td>\n<td>Certificates validated before updates install.<\/td>\n<\/tr>\n<tr>\n<td><strong>Auto-Updater Hardening<\/strong><\/td>\n<td>Removed libcurl.dll<\/td>\n<td>Eliminates DLL side-loading risk.<\/td>\n<\/tr>\n<tr>\n<td><strong>Stronger SSL<\/strong><\/td>\n<td>Disabled weak cURL options<\/td>\n<td>Enforces stricter TLS\/SSL validation.<\/td>\n<\/tr>\n<tr>\n<td><strong>Plugin Control<\/strong><\/td>\n<td>Signed plugins only<\/td>\n<td>Only plugins signed with official certificate allowed.<\/td>\n<\/tr>\n<tr>\n<td><strong>Stability &amp; Transparency<\/strong><\/td>\n<td>Bug fixes + public response<\/td>\n<td>Improves stability and maintains open communication post-incident.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Moreover, users who prefer manual update control can\u00a0turn off the auto-updater during installation\u00a0or use the MSI parameter:<\/p>\n<pre class=\"wp-block-code\"><code>msiexec \/i npp.8.9.2.Installer.x64.msi NOUPDATER=1<\/code><\/pre>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/notepad-v8-9-2-released\/\">Notepad++ v8.9.2 Released with \u201cDouble-Lock\u201d Update Mechanism Following Recent Hack<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/notepad-v8-9-2-released\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Notepad++ v8.9.2 Released with \u201cDouble-Lock\u201d Update Mechanism Following Recent Hack The widely used open-source text and code editor has released version\u00a0v8.9.2, introducing a major security enhancement known as the\u00a0\u201cDouble-Lock\u201d update mechanism. This update addresses vulnerabilities that were exploited in a recent state-sponsored attack\u00a0targeting the application\u2019s update infrastructure. Last month, Notepad++\u2019s official site confirmed that attackers [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-10740","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10740"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=10740"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/10740\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=10740"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=10740"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=10740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}