<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Security]]></title><description><![CDATA[Security shouldn&#x27;t be the privilege of rich people]]></description><link>https://community.notepad-plus-plus.org/category/9</link><generator>RSS for Node</generator><lastBuildDate>Sat, 18 Apr 2026 22:27:53 GMT</lastBuildDate><atom:link href="https://community.notepad-plus-plus.org/category/9.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 15 Apr 2026 09:23:22 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Libcurl in update is version 8.15.0, which is flagged with CVE-2025-14819 &#x2F; CVE-2025-14017, but the GUP uses version 8.19.0?]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/288">@xomx</a><br />
Thank you for pinging!<br />
<a href="https://github.com/notepad-plus-plus/notepad-plus-plus/commit/2c1abe0784543e78dbba0f259b0948cf3a08b8cb" rel="nofollow ugc">https://github.com/notepad-plus-plus/notepad-plus-plus/commit/2c1abe0784543e78dbba0f259b0948cf3a08b8cb</a></p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27493/libcurl-in-update-is-version-8-15-0-which-is-flagged-with-cve-2025-14819-cve-2025-14017-but-the-gup-uses-version-8-19-0</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27493/libcurl-in-update-is-version-8-15-0-which-is-flagged-with-cve-2025-14819-cve-2025-14017-but-the-gup-uses-version-8-19-0</guid><dc:creator><![CDATA[donho]]></dc:creator><pubDate>Wed, 15 Apr 2026 09:23:22 GMT</pubDate></item><item><title><![CDATA[Harmandeep Singh Kandhari - Enhancing Plugin Security and Preventing Malicious Code Execution]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/27184">@Coises</a></p>
<p dir="auto">Thank you, Coises, for your helpful reply. I truly appreciate your support and guidance.</p>
<p dir="auto">Regards,<br />
Harmandeep Singh Kandhari</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27417/harmandeep-singh-kandhari-enhancing-plugin-security-and-preventing-malicious-code-execution</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27417/harmandeep-singh-kandhari-enhancing-plugin-security-and-preventing-malicious-code-execution</guid><dc:creator><![CDATA[harmansinghdeepkandhari]]></dc:creator><pubDate>Tue, 17 Feb 2026 06:54:13 GMT</pubDate></item><item><title><![CDATA[FAQ: February Security Announcement]]></title><description><![CDATA[<p dir="auto">Updates with new clarifications from <a href="https://github.com/notepad-plus-plus/notepad-plus-plus/issues/17478#issuecomment-3865068368" rel="nofollow ugc">this comment</a>:</p>
Target Information
<p dir="auto">Kaspersky only saw evidence of victims IP addresses in Vietnam, El Salvador, Australia and the Philippines, and noted, “We observed three different infection chains overall, designed to attack about a dozen machines…”.</p>
<p dir="auto">Thus, it wasn’t just “targeted” – out of all the update attempts that would have happened during the June to December timeframe, it appears there were only a dozen victims: everyone else got a normal, unaffected update, with no malicious payload.</p>
Obvious Side-effect: Notepad++ Not Actually Updated after “Update”
<p dir="auto">When the attackers redirected victims, the victims got “updaters” which did nothing to notepad++.exe.  If every time that automatic updates ran, you saw Notepad++ actually updated, you were not one of the victims.</p>
<p dir="auto">In case the user runs Notepad++ updater, if the version remains exactly the same after the attempted update, the user can check %LOCALAPPDATA%\Notepad++\log\securityError.log to see what happened &amp; report it.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27388/faq-february-security-announcement</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27388/faq-february-security-announcement</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Wed, 04 Feb 2026 21:17:29 GMT</pubDate></item><item><title><![CDATA[I am very confused about the Notepad++ security issue]]></title><description><![CDATA[<p dir="auto">See the FAQ, which has the best summary I can make, as of 2026-Feb-04; if new information is available, the FAQ will be updated.  ALL followups/discussions must go in <a href="https://community.notepad-plus-plus.org/topic/27212/autoupdater-and-connection-temp-sh">Topic: autoupdater and connection to temp.sh</a>.  This tangent is LOCKED.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27387/i-am-very-confused-about-the-notepad-security-issue</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27387/i-am-very-confused-about-the-notepad-security-issue</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Wed, 04 Feb 2026 20:16:11 GMT</pubDate></item><item><title><![CDATA[Were the binaries released on GitHub affected in the Notepad++ state-sponsored hacking incident?]]></title><description><![CDATA[<p dir="auto">See the FAQ, which has the best summary I can make, as of 2026-Feb-04; if new information is available, the FAQ will be updated.  ALL followups/discussions must go in <a href="https://community.notepad-plus-plus.org/topic/27212/autoupdater-and-connection-temp-sh">Topic: autoupdater and connection to temp.sh</a>.  This tangent is LOCKED.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27386/were-the-binaries-released-on-github-affected-in-the-notepad-state-sponsored-hacking-incident</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27386/were-the-binaries-released-on-github-affected-in-the-notepad-state-sponsored-hacking-incident</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Wed, 04 Feb 2026 07:57:46 GMT</pubDate></item><item><title><![CDATA[Chinese compromise began as early as NP++ v8.6.9]]></title><description><![CDATA[<p dir="auto">Future readers: if you want more information for the context of this discussion, See the FAQ, which has the best summary I can make, as of 2026-Feb-04; if new information is available, the FAQ will be updated.  ALL followups/discussions must go in <a href="https://community.notepad-plus-plus.org/topic/27212/autoupdater-and-connection-temp-sh">Topic: autoupdater and connection to temp.sh</a>.  This tangent is LOCKED.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27383/chinese-compromise-began-as-early-as-np-v8-6-9</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27383/chinese-compromise-began-as-early-as-np-v8-6-9</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Tue, 03 Feb 2026 13:08:38 GMT</pubDate></item><item><title><![CDATA[notepad-plus-plus.org should be added to the HSTS preload list]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38110">@Ilhan-Yumer</a> ,</p>
<p dir="auto">The developer does not read most posts in this Forum.  If you would like to suggest such a move to the developer, I would recommend creating a new Issue at GitHub requesting it (<a href="https://github.com/notepad-plus-plus/notepad-plus-plus/issues" rel="nofollow ugc">https://github.com/notepad-plus-plus/notepad-plus-plus/issues</a>).</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27381/notepad-plus-plus-org-should-be-added-to-the-hsts-preload-list</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27381/notepad-plus-plus-org-should-be-added-to-the-hsts-preload-list</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Mon, 02 Feb 2026 23:19:45 GMT</pubDate></item><item><title><![CDATA[Advices to prevent further security vulnerabilities]]></title><description><![CDATA[<blockquote>
<p dir="auto">BTW:</p>
<blockquote>
<p dir="auto">5.1-if your home internet speed is fast enough, setup your own web server to your pc under virtualbox(in case of web server software cve’s/rce’s). I or anyone can help with that. Dont forget to hardening server for security.</p>
</blockquote>
<p dir="auto">IMO, this is <a href="#" title="Broken As Designed">BAD</a> advice.  To suggest to a non-security specialist who runs this as a hobby, that he should self-host, and try to keep up on all the security hardening, is asking him to get hacked even worse than the hack that already happened.  He was literally paying a host to provide such services, and the professionals failed; he has now changed providers to a host who has better security procedures.</p>
</blockquote>
<p dir="auto">Believe me it’s not that hard to setup a webserver or harden it, especially while backed by a strong community. The risks are different when hosting at home between hosting remotely. The hosting firm may be offered money to hijack, or an out-of-date hosting management software had rce was waiting to be abused.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27380/advices-to-prevent-further-security-vulnerabilities</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27380/advices-to-prevent-further-security-vulnerabilities</guid><dc:creator><![CDATA[Nppenjoyr]]></dc:creator><pubDate>Mon, 02 Feb 2026 19:30:41 GMT</pubDate></item><item><title><![CDATA[Help needed - Forensic extractor result analyzing]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/288">@xomx</a> said in <a href="/post/104352">Help needed - Forensic extractor result analyzing</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/3">@donho</a></p>
<p dir="auto">What is that for (is it for specific HW, OS or network analysis)?</p>
</blockquote>
<p dir="auto">Ubuntu on a VPS</p>
<blockquote>
<p dir="auto">Fullname of the forensic SW</p>
</blockquote>
<p dir="auto">“Forensic Extractor”</p>
<blockquote>
<p dir="auto"><a href="http://ballpoint.fr" rel="nofollow ugc">ballpoint.fr</a></p>
</blockquote>
<p dir="auto">It’s rather to analyze the results to make sure if anything is OK. Note the VPS is only for the <a href="http://wingup.org" rel="nofollow ugc">wingup.org</a>, whereas <a href="http://notepad-plus-plus.org" rel="nofollow ugc">notepad-plus-plus.org</a> is on a sharing hosting service.</p>
<p dir="auto">Thank you for the ref<br />
I will check this company.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27330/help-needed-forensic-extractor-result-analyzing</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27330/help-needed-forensic-extractor-result-analyzing</guid><dc:creator><![CDATA[donho]]></dc:creator><pubDate>Tue, 30 Dec 2025 04:04:51 GMT</pubDate></item><item><title><![CDATA[autoupdater and connection temp.sh]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/3">@donho</a> ,<br />
Thanks for the verifcation, and sorry for the late reponse, I came down really sick that night for about a 5 day period after posting this, and am just getting back into the swing of things. Just wanted to make sure we didn’t need to be redundant about that process.  Thanks again for the clarification.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27212/autoupdater-and-connection-temp-sh</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27212/autoupdater-and-connection-temp-sh</guid><dc:creator><![CDATA[Lycan Thrope]]></dc:creator><pubDate>Thu, 23 Oct 2025 18:53:02 GMT</pubDate></item><item><title><![CDATA[libcurl &lt; 8.14.1 CVE-2025-5399]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/36988">@Pulp-Sendo</a><br />
Already <a href="https://github.com/notepad-plus-plus/wingup/commit/696508ebe25bb78a07119e80644ac3a1f4341ea4" rel="nofollow ugc">fixed</a> for the upcoming N++ <a href="https://community.notepad-plus-plus.org/topic/27157/notepad-v8-8-6-release-candidate">v8.8.6</a>.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27173/libcurl-8-14-1-cve-2025-5399</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27173/libcurl-8-14-1-cve-2025-5399</guid><dc:creator><![CDATA[xomx]]></dc:creator><pubDate>Tue, 07 Oct 2025 05:05:17 GMT</pubDate></item><item><title><![CDATA[Notepad++ DLL Hijacking Vulnerability (CVE-2025-56383)]]></title><description><![CDATA[<p dir="auto"><a href="https://notepad-plus-plus.org/news/v886-released/" rel="nofollow ugc">https://notepad-plus-plus.org/news/v886-released/</a></p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27160/notepad-dll-hijacking-vulnerability-cve-2025-56383</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27160/notepad-dll-hijacking-vulnerability-cve-2025-56383</guid><dc:creator><![CDATA[donho]]></dc:creator><pubDate>Wed, 01 Oct 2025 18:36:49 GMT</pubDate></item><item><title><![CDATA[notepad++ flagged as malicious, should i worry?]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/288">@xomx</a> Thanks for your input, the analysis does seem to be a bit on the… overly cautious or paranoid side.<br />
maybe it’s time to find a new resource for risk analysis!</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27106/notepad-flagged-as-malicious-should-i-worry</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27106/notepad-flagged-as-malicious-should-i-worry</guid><dc:creator><![CDATA[Zhane Hernandez]]></dc:creator><pubDate>Wed, 27 Aug 2025 03:41:08 GMT</pubDate></item><item><title><![CDATA[Certificate install location]]></title><description><![CDATA[<p dir="auto"><strong>UPDATE</strong>: With the <a href="/topic/27203">release of v8.8.7</a>, Notepad++ is once again signed by a GlobalSign-issued certificate, as well as the Notepad++ self-signed certificate.</p>
<p dir="auto">The above instructions are still appropriate for confirming the self-signed certificate, but with the GlobalSign-issued certificate, the procedure is not as critical.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27028/certificate-install-location</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27028/certificate-install-location</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Wed, 23 Jul 2025 14:45:39 GMT</pubDate></item><item><title><![CDATA[File empty after opening it as Adminitrator]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/36138">@podlipom51-podlipom51</a> said in <a href="/post/102621">File empty after opening it as Adminitrator</a>:</p>
<blockquote>
<p dir="auto">I was unable to save file. Suggested to open as Administrator after accepting my file is empty. It is very important file for me what to do?</p>
</blockquote>
<p dir="auto">Where were you trying to save the file?  To somewhere in c:\program files\ or c:\windows or similarly protected area?  Or were you trying to save to a normal writeable directory on your machine’s local drive?  Or a mounted network drive?  Because it only suggests Administrator if it gets a “permission denied” error when you try to write the file.</p>
<blockquote>
<p dir="auto">after accepting my file is empty. It is very important file for me what to do?</p>
</blockquote>
<p dir="auto">Bummer.  Unfortunately, if you already restarted Notepad++, and it didn’t have the <strong>Settings &gt; Preferences &gt; Backup</strong> set to take “session snapshots and periodic backups”, your unsaved changes were never written to disk anywhere.  As soon as Notepad++ exited, those bits were removed from active memory, and were lost.  Since the files were likely never written to disk, I doubt that an external file-recovery utility like Recuva would work for you, but you might try directing such at the `c:\users&lt;username&gt;\AppData\Roaming\Notepad++\backup</p>
<p dir="auto">See our <a href="/topic/21782">FAQ on backups</a> for more details about how the Notepad++ backup settings work, how the AutoSave plugin can help improve things, and best-practice suggestions for avoiding data loss in the future.</p>
<p dir="auto">Also, I think one of the frequent contributors is actively working on a solution to have Notepad++ be able to get UAC permission for a file-save without needing to restart the application – such a feature would definitely help in your case.  Unfortunately, I’ve spent the last few minutes trying to find the Issue or PR where that was being discussed, and haven’t found it yet.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27020/file-empty-after-opening-it-as-adminitrator</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27020/file-empty-after-opening-it-as-adminitrator</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Fri, 18 Jul 2025 10:29:22 GMT</pubDate></item><item><title><![CDATA[Digital certificate for open source projects]]></title><description><![CDATA[<p dir="auto"><strong>UPDATE</strong>: With the <a href="/topic/27203">release of v8.8.7</a>, Notepad++ is once again signed by a GlobalSign-issued certificate, as well as the Notepad++ self-signed certificate.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/27019/digital-certificate-for-open-source-projects</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/27019/digital-certificate-for-open-source-projects</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Thu, 17 Jul 2025 12:19:02 GMT</pubDate></item><item><title><![CDATA[Mc afee détecte également un virus sur la version 8.8.2 64 bits.]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/35957">@Joël-PLANCHAT</a> ,</p>
<p dir="auto">False Positive caused because there is no certificate:</p>
<p dir="auto">KNOWN ISSUE: <a href="https://community.notepad-plus-plus.org/topic/26978/known-issue-the-digital-certificate-is-not-available-in-version-8-8-2">https://community.notepad-plus-plus.org/topic/26978/known-issue-the-digital-certificate-is-not-available-in-version-8-8-2</a></p>
<p dir="auto">–</p>
<p dir="auto"><strong>UPDATE</strong>: With the <a href="/topic/27203">release of v8.8.7</a>, Notepad++ is once again signed by a GlobalSign-issued certificate, as well as the Notepad++ self-signed certificate.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/26985/mc-afee-détecte-également-un-virus-sur-la-version-8-8-2-64-bits</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/26985/mc-afee-détecte-également-un-virus-sur-la-version-8-8-2-64-bits</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Thu, 03 Jul 2025 12:14:07 GMT</pubDate></item><item><title><![CDATA[KNOWN ISSUE: The digital certificate is not available in version 8.8.2.]]></title><description><![CDATA[<p dir="auto"><strong>UPDATE</strong>: With the <a href="/topic/27203">release of v8.8.7</a>, Notepad++ is once again signed by a GlobalSign-issued certificate, as well as the Notepad++ self-signed certificate.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/26978/known-issue-the-digital-certificate-is-not-available-in-version-8-8-2</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/26978/known-issue-the-digital-certificate-is-not-available-in-version-8-8-2</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Tue, 01 Jul 2025 12:03:40 GMT</pubDate></item><item><title><![CDATA[Security of Legacy Notepad++ Versions (CVE-2025-49144)]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/35924">@Bhaalthazar</a> said in <a href="/post/102328">Security of Legacy Notepad++ Versions (CVE-2025-49144)</a>:</p>
<blockquote>
<p dir="auto">patching older vulnerable versions</p>
</blockquote>
<p dir="auto">It could be fun, now without the public CA cert available…</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/26977/security-of-legacy-notepad-versions-cve-2025-49144</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/26977/security-of-legacy-notepad-versions-cve-2025-49144</guid><dc:creator><![CDATA[xomx]]></dc:creator><pubDate>Tue, 01 Jul 2025 06:09:53 GMT</pubDate></item><item><title><![CDATA[Notepad v8.8.2 32-bit installer: virus or malware detected]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/38096">@Tavi</a> ,</p>
<p dir="auto">As far as I can tell, they were unrelated.  Scanners such as VirusTotal look at the executable itself, and last year were being triggered by the lack of signing and the self-signing of the executable.</p>
<blockquote>
<p dir="auto">please confirm if this issue is related to the notepad++ hijack news dated 2nd Feb 2026?</p>
</blockquote>
<p dir="auto">The issue you are referring to, as <a href="https://community.notepad-plus-plus.org/post/104567">linked here</a> and described in detail <a href="https://notepad-plus-plus.org/news/hijacked-incident-info-update/" rel="nofollow ugc">here</a> specifically said,</p>
<blockquote>
<p dir="auto">the compromise occured at the hosting provider level rather than through vulnerabilities in Notepad++ code itself.</p>
</blockquote>
<p dir="auto">This was a website hack, and VirusTotal and other such AV scans do not detect website hacks, as far as I understand them.</p>

<p dir="auto">See the FAQ, which has the best “table of contents” for the website hack.  ALL related followups/discussions must go in <a href="https://community.notepad-plus-plus.org/topic/27212/autoupdater-and-connection-temp-sh">Topic: autoupdater and connection to temp.sh</a>.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/26976/notepad-v8-8-2-32-bit-installer-virus-or-malware-detected</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/26976/notepad-v8-8-2-32-bit-installer-virus-or-malware-detected</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Mon, 30 Jun 2025 19:54:37 GMT</pubDate></item><item><title><![CDATA[Lock file]]></title><description><![CDATA[<p dir="auto">Here’s my reply:<br />
<a href="https://github.com/notepad-plus-plus/notepad-plus-plus/issues/16638#issuecomment-2947240947" rel="nofollow ugc">https://github.com/notepad-plus-plus/notepad-plus-plus/issues/16638#issuecomment-2947240947</a></p>
]]></description><link>https://community.notepad-plus-plus.org/topic/26926/lock-file</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/26926/lock-file</guid><dc:creator><![CDATA[donho]]></dc:creator><pubDate>Thu, 05 Jun 2025 20:23:38 GMT</pubDate></item><item><title><![CDATA[Fighting Malicious Ads on Download Pages]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/36998">@MarcCMcC</a> said in <a href="/post/103437">Fighting Malicious Ads on Download Pages</a>:</p>
<blockquote>
<p dir="auto">There are definitely still giant, green “Download” button ads:</p>
</blockquote>
<p dir="auto">Posting screenshots here isn’t helpful, at this point.</p>
<p dir="auto">And it is better if you just email the malicious links directly to  <a href="mailto:don.h@free.fr" rel="nofollow ugc">don.h@free.fr</a> , as has been said repeatedly in this discussion.</p>
<p dir="auto">–</p>
<p dir="auto">I am locking this thread, as there isn’t anything new to say about this topic</p>
<p dir="auto">–</p>
<p dir="auto">If you came here to report a malicious/dangerous download link (and NOTE: not all ads with “download” are malicious or dangerous), then</p>
e-mail the URLs for malicious or dangerous advertising links on that page directly to <a href="mailto:don.h@free.fr" rel="nofollow ugc">don.h@free.fr</a>
]]></description><link>https://community.notepad-plus-plus.org/topic/26920/fighting-malicious-ads-on-download-pages</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/26920/fighting-malicious-ads-on-download-pages</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Sun, 01 Jun 2025 11:27:21 GMT</pubDate></item><item><title><![CDATA[Limit the list of plugins employees can install.]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/31927">@Emmanuel-Meekers</a><br />
AFAIK there is no technical means to limit the number of plugins a user is able to install. You can only remove the capability to install plugins at all.</p>
<p dir="auto">You could do a survey which plugins your employees need. There can be different needs, e.g. technical staff likely needs other plugins than employees that ar more involved in administrative tasks. Then you can install these plugins on the employee’s machines.</p>
<p dir="auto">After that you need to rename or delete &lt;install-directory&gt;\updater\GUP.exe to prevent users from installing any other plugins. As long as your employees don’t have admin access to   Notepad++'s install directory, they are not able to revert these changes.</p>
<p dir="auto">The disadvantage is that your users neither will be able to update Notepad++ itself nor the installed plugins. This is something your ICT department has to do.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/26166/limit-the-list-of-plugins-employees-can-install</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/26166/limit-the-list-of-plugins-employees-can-install</guid><dc:creator><![CDATA[dinkumoil]]></dc:creator><pubDate>Tue, 01 Oct 2024 06:34:40 GMT</pubDate></item><item><title><![CDATA[Does NP++ Mini-Portable cache or save files on host system when run from USB stick]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/7377">@Alan-Kilborn</a> So where should this be discussed then?</p>
<p dir="auto">I would greatly appreciate if anyone did know of some little FOOS tool/script like I mentioned, more reliable than what I’ve hacked together, to help me secure my friends cyber security.</p>
<p dir="auto">Can people here DM me suggestions?</p>
<p dir="auto">If there was a discord this could be spun off into a thread.</p>
<p dir="auto">I’m not sure if it matters to anyone but the suggestions and discussion so far have been really helpful and spot on solving the problem which I’m still using NPP for BTW (such as displaying instructions as we just discussed).</p>
<p dir="auto">For some perspective, the person I’m trying to help recently lost 7kg in just over a week due to stress and worry from being targeted and harassed by some hacker/scammer that’s been messing with then, trying to take accounts etc for a while now.</p>
<p dir="auto">I agree it’s not on strictly topic and I don’t expect to discuss this here, it’s just without at least giving a way to continue the discussion elsewhere, given the fact that it’s still directly addressing the goal I initially stated, and the potential consequences to people, it seems kinda callous to just stomp on it like we’re posting cat memes.</p>
<p dir="auto">So how and where should this be continued, or is that irrelevant?</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/26112/does-np-mini-portable-cache-or-save-files-on-host-system-when-run-from-usb-stick</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/26112/does-np-mini-portable-cache-or-save-files-on-host-system-when-run-from-usb-stick</guid><dc:creator><![CDATA[Nommy]]></dc:creator><pubDate>Fri, 13 Sep 2024 10:39:33 GMT</pubDate></item><item><title><![CDATA[Notepadd++ General version update function]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="https://community.notepad-plus-plus.org/uid/31512">@Izzy-Gonzalez</a> said in <a href="/post/96453">Notepadd++ General version update function</a>:</p>
<blockquote>
<p dir="auto">Is there any way to allow a normal user to update the software without having to provide the user admin rights to the local PC?</p>
</blockquote>
<p dir="auto">Microsoft has defined C:\Program Files\ (and equivalent, though I’ll use that as the generic path going forward in this post) as requiring UAC (elevated privileges, or “Admin privileges”).  If someone installs Notepad++ into C:\Program Files\Notepad++\, then it will require admin rights (unless you have disabled UAC on your PC).</p>
<p dir="auto">If you cannot disable UAC requirements, you could try changing the permission of the C:\Program Files\Notepad++\ directory (and all subdirectories) – which will require UAC/Admin once to be able to change the permissions, but should successfully update thereafter.  (That’s what I do on my work machine, since I frequently update Notepad++ or its plugins, and got tired of entering my password every time I did.)</p>
<p dir="auto">If changing permissions of the installation directory is not something you’re interested in, you might consider installing Notepad++ to a location where you do have write access, instead of in the default C:\Program Files\Notepad++\ – maybe you could create a directory called C:\LocalApps\, and install Notepad++ as C:\LocalApps\Notepad++\ .  As long as you installed it as your local, non-privileged user and have appropriate permissions in the C:\LocalApps\ hierarchy, you shouldn’t be pestered for Admin rights on future updates.</p>
]]></description><link>https://community.notepad-plus-plus.org/topic/26088/notepadd-general-version-update-function</link><guid isPermaLink="true">https://community.notepad-plus-plus.org/topic/26088/notepadd-general-version-update-function</guid><dc:creator><![CDATA[PeterJones]]></dc:creator><pubDate>Fri, 06 Sep 2024 15:07:28 GMT</pubDate></item></channel></rss>