Daily Digest

Notepad++ Supply Chain Attack by Chinese APT; Russian Group Exploits Office Zero-Day

Notepad++ Supply Chain Attack by Chinese APT; Russian Group Exploits Office Zero-Day

February 3, 2026
11 articles (8 new, 3 updated)
33 min read

Summary

A sophisticated supply chain attack targeting the popular Notepad++ editor, attributed to the Chinese APT group Lotus Blossom, has been uncovered, selectively deploying malware to users in Southeast Asia. Concurrently, the Russian-backed APT28 is actively exploiting a new Microsoft Office zero-day vulnerability (CVE-2026-21509) to target entities in Eastern Europe. Ransomware remains a dominant threat, with the Qilin group claiming an attack on Tulsa International Airport and other groups targeting US law firms and manufacturing. These events highlight a landscape of escalating state-sponsored espionage and persistent criminal activity targeting critical infrastructure and corporate entities.

Filter by Category

New Articles (8)

Updated Articles (3)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.