Threats & Adversaries · APT / Espionage

State-Linked Campaigns Hit Notepad++ and AI Ecosystems

Russia-linked APT28 weaponised CVE-2026-21509 against targets in Central and Eastern Europe. China-linked Lotus Blossom compromised the Notepad++ supply chain.

1 source · Mar 2

CVE-2026-21509

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a… EPSS 73% (99th percentile).

CISA federal remediation date Feb 16 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-03-03

Every edition of this story: State-Linked Campaigns Hit Notepad++ and AI Ecosystems

More from today