Rapid7 links China-linked Lotus Blossom to a 2025 Notepad++ hosting breach that delivered the Chrysalis backdoor via hijacked updates, fixed in v8.8.9 ...
A Chinese-linked cyberespionage group named Lotus Blossom hijacked the update process of Notepad++ to target specific users. Gaining access in June 2025, they maintained control until December that ...
A recent supply-chain-style intrusion has put a spotlight on a familiar truth in cybersecurity: attackers don’t always need to hack ...
The group targets telecoms, critical infrastructure - all the usual high-value orgs Security researchers have attributed the ...
Chinese state-sponsored threat actors were likely behind the hijacking of Notepad++ update traffic last year that lasted for almost half a year, the developer states in an official announcement today.
The pages feature Rocksteady and Bebop confronting Lotus Blossom in a dojo, most likely when the evil Krang tries to recruit Lotus Blossom to help them steal the Turtles’ portable dimensional window.