Daily Digest

Notepad++ Supply Chain Attack by Chinese APT; Russian Group Exploits Office Zero-Day

Notepad++ Supply Chain Attack by Chinese APT; Russian Group Exploits Office Zero-Day

February 3, 2026
11 articles (8 new, 3 updated)
33 min read

Summary

A sophisticated supply chain attack targeting the popular Notepad++ editor, attributed to the Chinese APT group Lotus Blossom, has been uncovered, selectively deploying malware to users in Southeast Asia. Concurrently, the Russian-backed APT28 is actively exploiting a new Microsoft Office zero-day vulnerability (CVE-2026-21509) to target entities in Eastern Europe. Ransomware remains a dominant threat, with the Qilin group claiming an attack on Tulsa International Airport and other groups targeting US law firms and manufacturing. These events highlight a landscape of escalating state-sponsored espionage and persistent criminal activity targeting critical infrastructure and corporate entities.

Filter by Category

New Articles (8)

Updated Articles (3)

📢 Share This Publication

Help others stay informed about cybersecurity threats