State-Linked Campaigns Hit Notepad++ and AI Ecosystems

Russia-linked APT28 weaponised CVE-2026-21509 against targets in Central and Eastern Europe. China-linked Lotus Blossom compromised the Notepad++ supply chain.

Part of the PlainSec briefing for 2026-03-03

Sources