Find notable cyber news and cases, enriched with sources, timelines, and signals.

CERT-UA update advice for Notepad++, 7-Zip, and WinRAR

Advisory/Mitigation
First reported
Last updated
Happening score
H score 15
1 unique sources, 1 articles

Summary

Hide ▲

CERT-UA told administrators to update Notepad++, 7-Zip, and WinRAR after attackers abused the software in a stealthy delivery chain. The guidance targets known flaws and reduces the risk of malicious plugin loading and related abuse in affected environments. The advisory is tied to a live attack pattern against systems used by organizations in Ukraine.

Related Happenings

UAC-0099 Notepad++ plugin delivery campaign targeting organizations in Ukraine

Campaign
H score33 First: 23.07.2026 19:32 Last: 23.07.2026 19:32 Sources 1

How related: The campaign has been attributed to a threat cluster tracked as UAC-0099, which primarily targets organizations in Ukraine and has previously been linked to providing initial access for attacks carried out by APT44, also known as Sandworm.

About this happening: The UAC-0099 campaign is distributing ZIP/VBS lures that load a malicious Notepad++ plugin to establish persistence and stage additional tooling for organizations in...

Turla STOCKSTAY .NET backdoor deployment

Malware Activity
H score27 First: 26.06.2026 10:15 Last: 26.06.2026 10:15 Sources 1

About this happening: Turla's STOCKSTAY backdoor has been newly detailed as a .NET espionage implant used against government and military organizations in Ukraine and entities linked to I...

Turla STOCKSTAY phishing campaign targeting Ukraine and Europe

Campaign
H score37 First: 26.06.2026 10:15 Last: 26.06.2026 10:15 Sources 1

About this happening: Turla's STOCKSTAY phishing campaign is targeting government and military organizations in Ukraine and selected European entities, extending a recurring espionage opera...

AGEWHEEZE remote access trojan activity

Malware Activity
H score43 First: 01.04.2026 19:10 Last: 01.04.2026 19:10 Sources 1

About this happening: CERT-UA disclosed AGEWHEEZE, a remote access trojan delivered through a password-protected ZIP that enabled remote control over infected devices. The malware was sprea...

Notepad++ hit by network compromise

Incident
H score17 First: 03.02.2026 06:55 Last: 03.02.2026 06:55 Sources 1

About this happening: The Notepad++ hosting breach enabled attackers to hijack the software update path and selectively redirect some users to malicious servers, creating a supply-chain ris...

Latest development: 18.02.2026 09:40

Notepad++ released version 8.9.2 to harden the update mechanism after the hijacked update path was used to deliver targeted malware. The release adds a "double lock" design with verification of the signed installer downloaded from GitHub and verification of the signed XML returned by the update server at notepad-plus-plus[.]org, and it also introduces WinGUp hardening including removal of libcurl.dll, removal of CURLSSLOPT_ALLOW_BEAST and CURLSSLOPT_NO_REVOKE, and restriction of plugin management execution to programs signed with the same certificate as WinGUp.

Timeline

  1. 23.07.2026 19:32 2 articles · 1h ago

    CERT-UA urges updates to Notepad++, 7-Zip, and WinRAR

    Mitigation Patch Update

    CERT-UA advised system administrators to update Notepad++ to version 8.9.7, 7-Zip to version 26.02, and WinRAR to version 7.23 after UAC-0099 used a ZIP/VBS delivery chain with a disguised PDF, a malicious Notepad++ plugin, and related loaders to enable stealthy attacks.

    Show sources