<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>website &#8211; EmEditor (Text Editor)</title>
	<atom:link href="/tag/home-page/feed/index.xml" rel="self" type="application/rss+xml" />
	<link>/</link>
	<description>Best Text Editor, Code Editor, CSV Editor, Large File Viewer for Windows (Free versions available)</description>
	<lastBuildDate>Sat, 30 May 2026 00:56:36 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.2</generator>

<image>
	<url>/wp-content/uploads/2024/09/icon-36x36.png</url>
	<title>website &#8211; EmEditor (Text Editor)</title>
	<link>/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Emurasoft Receives Excellence Award at the 11th Information Security Incident Response Awards</title>
		<link>/reviews/11th-incident-response-award/</link>
		
		<dc:creator><![CDATA[Yutaka Emura]]></dc:creator>
		<pubDate>Sat, 30 May 2026 00:56:35 +0000</pubDate>
				<category><![CDATA[Reviews]]></category>
		<category><![CDATA[award]]></category>
		<category><![CDATA[website]]></category>
		<guid isPermaLink="false">/?p=30804</guid>

					<description><![CDATA[We are honored to announce that Emurasoft, Inc. received the Excellence Award at the 11th Information Security Incident Response Awards, hosted by Mynavi News, on May 14, 2026, in Tokyo, Japan. This year, five selection committee members, all active experts in Japan’s security industry, reviewed numerous security incidents that occurred between January and December 2025. [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">We are honored to announce that Emurasoft, Inc. received the Excellence Award at the 11th Information Security Incident Response Awards, hosted by Mynavi News, on May 14, 2026, in Tokyo, Japan.</p>



<p class="wp-block-paragraph">This year, five selection committee members, all active experts in Japan’s security industry, reviewed numerous security incidents that occurred between January and December 2025. Among them, 25 cases were nominated for their outstanding incident response efforts, and organizations that demonstrated particularly effective responses were recognized.</p>



<ul class="wp-block-list">
<li><a href="https://news.mynavi.jp/techplus/article/20260529-4472296/" target="_blank" rel="noreferrer noopener">Cyber Threats Have Become Incomparably More Sophisticated Over the Past 10 Years — EmEditor Developer Discusses the Reality of Supply Chain Attacks After Receiving the Award for the Second Time (Japanese)</a></li>



<li><a href="https://news.mynavi.jp/techplus/article/20260529-4482182/" target="_blank" rel="noreferrer noopener">11th Information Security Incident Response Awards Recognize Outstanding Incident Responses (Japanese)</a></li>
</ul>



<p class="wp-block-paragraph">We would like to once again express our sincere apologies for the inconvenience caused by this incident. We are deeply grateful for your prompt response, understanding, and cooperation throughout this matter.</p>



<p class="wp-block-paragraph">We remain committed to further strengthening our security measures and continuing to provide reliable software and services to our customers.</p>



<p class="wp-block-paragraph">Thank you for your continued support of EmEditor.</p>



<p class="wp-block-paragraph"><strong>References:</strong></p>



<p class="wp-block-paragraph"><a href="https://jp.emeditor.com/reviews/4c4c565064787c36720ef24f9952c64e/">Emurasoft Receives Excellence Award at the 1st Security Incident Response Awards (Japanese)</a></p>



<p class="wp-block-paragraph"><a href="https://www.emeditor.com/general/important-follow-up-security-incident-notice-regarding-the-emeditor-installer-download-link/">[Important] Security Incident Regarding the Download Path for the EmEditor Installer — Additional Information and Summary</a></p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Domain Changes as Part of Security Improvements</title>
		<link>/general/domain-changes-as-part-of-security-improvements/</link>
		
		<dc:creator><![CDATA[Yutaka Emura]]></dc:creator>
		<pubDate>Tue, 21 Apr 2026 00:08:26 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[website]]></category>
		<guid isPermaLink="false">/?p=30764</guid>

					<description><![CDATA[As part of our ongoing efforts to enhance security, we will be updating the domains used for Help and downloads: With this change, all of our official resources will be hosted on emeditor.com or its subdomains. When you see emeditor.com in the URL, you can be confident that the site is authentic and secure. If [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">As part of our ongoing efforts to enhance security, we will be updating the domains used for Help and downloads:</p>



<ul class="wp-block-list">
<li><strong>Help:</strong> <code>https://www.emeditor.org/</code> → <code>https://help.emeditor.com/</code></li>



<li><strong>Downloads:</strong> <code>https://download.emeditor.info/</code> → <code>https://download.emeditor.com/</code></li>
</ul>



<p class="wp-block-paragraph">With this change, all of our official resources will be hosted on <code>emeditor.com</code> or its subdomains. When you see <code>emeditor.com</code> in the URL, you can be confident that the site is authentic and secure.</p>



<p class="wp-block-paragraph">If you visit the current domains, you will be automatically redirected to the new ones, so <strong>no action is required on your part</strong> unless you are an IT administrator. This change is scheduled for May 4, 2026.</p>



<h3 class="wp-block-heading">Note for IT Administrators</h3>



<p class="wp-block-paragraph">If your organization uses a firewall to control EmEditor downloads, please whitelist <code>download.emeditor.com</code> (ports 80 and 443) for the program <code>eeupdate.exe</code> to ensure uninterrupted delivery of updates.</p>



<p class="wp-block-paragraph">See also &#8220;<a href="/faq/downloads-faq/what-are-the-emeditor-subdomains/">What are the EmEditor subdomains?</a>&#8220;</p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>EmEditor Is Now Even More Secure to Download</title>
		<link>/general/emeditor-is-now-even-more-secure-to-download/</link>
		
		<dc:creator><![CDATA[Yutaka Emura]]></dc:creator>
		<pubDate>Mon, 12 Jan 2026 22:52:21 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[website]]></category>
		<guid isPermaLink="false">/?p=30637</guid>

					<description><![CDATA[EmEditor Is Now Even Safer and Easier to Get The EmEditor desktop installer is now also available from the Microsoft Store.The desktop installer available on the Microsoft Store is the same program for both EmEditor Professional and EmEditor Free (you get the same app and use it according to your license/usage). We have also improved our official website [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>EmEditor Is Now Even Safer and Easier to Get</strong></p>



<p class="wp-block-paragraph">The EmEditor desktop installer is now also available from the <strong><a href="https://apps.microsoft.com/detail/XP9JZPSPCXGJX4?referrer=blogtext&amp;mode=full" target="_blank" rel="noreferrer noopener">Microsoft Store</a></strong>.<br>The desktop installer available on the Microsoft Store is the <strong>same program</strong> for both <strong>EmEditor Professional</strong> and <strong>EmEditor Free</strong> (you get the same app and use it according to your license/usage).</p>



<p class="wp-block-paragraph">We have also improved our official website (<a href="http://www.emeditor.com/">www.emeditor.com</a>) so you can download EmEditor with greater peace of mind.</p>



<ul class="wp-block-list">
<li>The EmEditor <strong>desktop installer</strong> is now available from the <strong>Microsoft Store</strong>.</li>



<li>Even if you cannot use the Microsoft Store, you can still download the <strong>desktop installer</strong> safely from our official website.</li>



<li>Our website has been rebuilt as a <strong>static HTML-based site</strong>, which helps reduce risks such as website tampering compared to a dynamic site.</li>



<li>This website is now hosted on Cloudflare Workers, giving us tightly controlled security. Cloudflare’s role‑based access control and enterprise-grade authentication standards help ensure only authorized changes are made, so you can trust that the content you see comes from us.</li>
</ul>



<p class="wp-block-paragraph">We will continue to provide <strong>only official installers</strong>&nbsp;through our website and other authorized distribution channels.<br><em>For your safety, please download EmEditor from trusted sources such as our official website or the Microsoft Store.</em></p>



<p style="text-align: center;"><a href="https://apps.microsoft.com/detail/XP9JZPSPCXGJX4?referrer=blogbutton&amp;mode=full" target="_blank" rel="noopener"><img decoding="async" src="https://get.microsoft.com/images/en-us%20dark.svg" width="200" /></a></p>
<p style="text-align: center;"><a href="https://apps.microsoft.com/detail/XP9JZPSPCXGJX4?referrer=blogtext&amp;mode=full" target="_blank" rel="noopener">Download from Microsoft Store</a></p>
<p style="text-align: center;"><a href="/download/">Other downloads</a></p>



<p class="wp-block-paragraph"></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>New static, HTML-based websites</title>
		<link>/general/new-static-html-based-websites/</link>
		
		<dc:creator><![CDATA[Yutaka Emura]]></dc:creator>
		<pubDate>Sat, 03 Jan 2026 23:51:30 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[website]]></category>
		<guid isPermaLink="false">/?p=30561</guid>

					<description><![CDATA[To reduce the security risks associated with WordPress, we’ve migrated our websites to static, HTML-based sites. As a result, the likelihood of future security incidents is expected to be extremely low. As part of this transition, our forums are now available in read-only mode. Thank you for your understanding.]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">To reduce the security risks associated with WordPress, we’ve migrated our websites to static, HTML-based sites. As a result, the likelihood of future security incidents is expected to be extremely low.</p>



<p class="wp-block-paragraph">As part of this transition, our forums are now available in read-only mode.</p>



<p class="wp-block-paragraph">Thank you for your understanding.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>[Important] Follow-up: Security Incident Notice Regarding the EmEditor Installer Download Link</title>
		<link>/general/important-follow-up-security-incident-notice-regarding-the-emeditor-installer-download-link/</link>
		
		<dc:creator><![CDATA[Yutaka Emura]]></dc:creator>
		<pubDate>Mon, 29 Dec 2025 22:57:40 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[incident]]></category>
		<category><![CDATA[website]]></category>
		<guid isPermaLink="false">https://www.emeditor.com/?p=30538</guid>

					<description><![CDATA[Following our earlier announcement, “[Important] Security Incident Notice Regarding the EmEditor Installer Download Link”, we are sharing what we have learned through further investigation, along with additional details that supplement the previous notice. We sincerely apologize once again for the serious concern and inconvenience this incident has caused. 1. Time Period Potentially Affected (U.S. Pacific [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Following our earlier announcement, <a href="/general/important-security-incident-notice-regarding-the-emeditor-installer-download-link/" target="_blank" rel="noreferrer noopener">“[Important] Security Incident Notice Regarding the EmEditor Installer Download Link”</a>, we are sharing what we have learned through further investigation, along with additional details that supplement the previous notice.</p>



<p class="wp-block-paragraph">We sincerely apologize once again for the serious concern and inconvenience this incident has caused.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">1. Time Period Potentially Affected (U.S. Pacific Time / UTC)</h3>



<p class="wp-block-paragraph">In our previous notice, we provided the timeframe in U.S. Pacific Time. For reference, we also include Coordinated Universal Time (UTC).</p>



<ul class="wp-block-list">
<li><strong>Dec 19, 2025 18:39 – Dec 22, 2025 12:50 (U.S. Pacific Time)</strong></li>



<li><strong>2025-12-20 02:39 – 2025-12-22 20:50 (UTC)</strong></li>
</ul>



<p class="wp-block-paragraph">If you downloaded the installer during the period above via the EmEditor website download path (for example, the “Download Now” button), there is a possibility that you downloaded a file that was <strong>not</strong> the legitimate installer provided by us (Emurasoft, Inc.).</p>



<p class="wp-block-paragraph">Please note that the period above is intentionally broad out of an abundance of caution. The actual window may have been shorter and limited to specific times.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">2. About the Suspicious File (Confirmed Differences)</h3>



<p class="wp-block-paragraph">For the file <strong><code>emed64_25.4.3.msi</code></strong>, we have confirmed the existence of at least <strong>two suspicious files</strong>.</p>



<p class="wp-block-paragraph">We also confirmed that both suspicious files were signed with <strong>Microsoft-issued digital signatures</strong>. Because the validity periods were extremely short (only a few days), we believe the certificates were likely issued in a manner similar to developer-oriented issuance.</p>



<p class="wp-block-paragraph">We reported this incident to Microsoft, provided the suspicious files, and requested revocation of the relevant signatures. We have now confirmed that <strong>both signatures have been revoked</strong>. As a result, attempting to run the MSI should display a warning that the signature is invalid, making installation difficult.</p>



<h4 class="wp-block-heading">Legitimate file (official EmEditor installer)</h4>



<ul class="wp-block-list">
<li>File name: <strong>emed64_25.4.3.msi</strong></li>



<li>Size: <strong>80,376,832 bytes</strong></li>



<li>Digital signature — Subject: <strong>Emurasoft, Inc.</strong></li>



<li>Digital signature — Issuer: <strong>Sectigo Public Code Signing CA R36</strong></li>



<li>Digital signature — Validity: <strong>Apr 9, 2023 to Apr 9, 2026</strong></li>



<li><strong>SHA-256:</strong> <code>e5f9c1e9b586b59712cefa834b67f829ccbed183c6855040e6d42f0c0c3fcb3e</code></li>



<li>VirusTotal:<br><a href="https://www.virustotal.com/gui/file/e5f9c1e9b586b59712cefa834b67f829ccbed183c6855040e6d42f0c0c3fcb3e" target="_blank" rel="noreferrer noopener">https://www.virustotal.com/gui/file/e5f9c1e9b586b59712cefa834b67f829ccbed183c6855040e6d42f0c0c3fcb3e</a></li>



<li>Official distribution source: <a href="https://download.emeditor.info/emed64_25.4.3.msi">https://download.emeditor.info/emed64_25.4.3.msi</a></li>
</ul>



<h4 class="wp-block-heading">Problematic file #1</h4>



<ul class="wp-block-list">
<li>File name: <code>emed64_25.4.3.msi</code></li>



<li>Size: <strong>80,380,416 bytes</strong></li>



<li>Digital signature — Subject: <strong>WALSHAM INVESTMENTS LIMITED</strong></li>



<li>Digital signature — Issuer: <strong>Microsoft ID Verified CS EOC CA 02</strong></li>



<li>Digital signature — Validity: <strong>Dec 21, 2025 to Dec 24, 2025</strong></li>



<li><strong>SHA-256:</strong> <code>4bea333d3d2f2a32018cd6afe742c3b25bfcc6bfe8963179dad3940305b13c98</code></li>



<li>VirusTotal:<br><a href="https://www.virustotal.com/gui/file/4bea333d3d2f2a32018cd6afe742c3b25bfcc6bfe8963179dad3940305b13c98" target="_blank" rel="noreferrer noopener">https://www.virustotal.com/gui/file/4bea333d3d2f2a32018cd6afe742c3b25bfcc6bfe8963179dad3940305b13c98</a></li>
</ul>



<h4 class="wp-block-heading">Problematic file #2</h4>



<ul class="wp-block-list">
<li>File name: <code>emed64_25.4.3.msi</code></li>



<li>Size: <strong>80,380,416 bytes</strong></li>



<li>Digital signature — Subject: <strong>WALSHAM INVESTMENTS LIMITED</strong></li>



<li>Digital signature — Issuer: <strong>Microsoft ID Verified CS EOC CA 01</strong></li>



<li>Digital signature — Validity: <strong>Dec 20, 2025 to Dec 23, 2025</strong></li>



<li><strong>SHA-256:</strong> <code>3d1763b037e66bbde222125a21b23fc24abd76ebab40589748ac69e2f37c27fc</code></li>



<li>VirusTotal:<br><a href="https://www.virustotal.com/gui/file/3d1763b037e66bbde222125a21b23fc24abd76ebab40589748ac69e2f37c27fc" target="_blank" rel="noreferrer noopener">https://www.virustotal.com/gui/file/3d1763b037e66bbde222125a21b23fc24abd76ebab40589748ac69e2f37c27fc</a></li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">3. If You Already Deleted the Downloaded File</h3>



<p class="wp-block-paragraph">If you still have the downloaded file (<code>emed64_25.4.3.msi</code>), you can verify it (as previously announced) by checking the <strong>digital signature</strong> and/or <strong>SHA-256</strong>.</p>



<p class="wp-block-paragraph">Even if you already deleted the file, Windows may have kept a copy of the MSI used during installation under <strong><code>C:\Windows\Installer</code></strong>, stored under a different name.</p>



<p class="wp-block-paragraph">Because this folder is both hidden and protected by the OS, it can be difficult to locate through normal File Explorer browsing. Please open it directly by entering: <strong><code>C:\Windows\Installer</code></strong>.</p>



<p class="wp-block-paragraph">After opening the folder, we recommend the steps below. Please be extremely careful <strong>not to double-click or run any MSI files</strong>.</p>



<ol class="wp-block-list">
<li><strong>Sort by date</strong> (for example, “Date modified”)</li>



<li>Focus on <strong>recent files</strong></li>



<li>Check the target file’s <strong>digital signature</strong> (Right-click → Properties → Digital Signatures)</li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">4. How To Check whether Your Computer May be Infected</h3>



<p class="wp-block-paragraph">Even if the suspicious file was executed, infection is not guaranteed in environments such as:</p>



<ul class="wp-block-list">
<li>The device was offline</li>



<li>A VPN/proxy was required</li>



<li>Suspicious PowerShell behavior was blocked by Windows features or policies</li>



<li>PowerShell execution was restricted</li>



<li>Antivirus/security software blocked the activity</li>
</ul>



<p class="wp-block-paragraph">However, if <strong>any</strong> of the following apply, the likelihood of infection becomes very high:</p>



<ul class="wp-block-list">
<li><code>C:\ProgramData\tmp_mojo.log</code> exists</li>



<li>A scheduled task named <strong><code>Google Drive Caching</code></strong> exists</li>



<li><strong><code>background.vbs</code></strong> exists in <code>%LOCALAPPDATA%\Google Drive Caching\</code></li>



<li>A browser extension named <strong><code>Google Drive Caching</code></strong> exists in a Chromium-based browser such as Chrome or Microsoft Edge (even if it claims to be made by Google)—especially if it can “read and change data on all websites” and has clipboard access</li>



<li>Network logs show connections to any of the following:</li>



<li><code>cachingdrive[.]com</code></li>



<li><code>emeditorde[.]com</code></li>



<li><code>emeditorgb[.]com</code></li>



<li><code>emeditorjp[.]com</code></li>



<li><code>emeditorsb[.]com</code></li>
</ul>



<p class="wp-block-paragraph">If none of the above apply, the risk is lower—but not zero—because part of the attack can run in memory and leave little or no file-based evidence.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">5. Confirmed Behavior (Destination Domains, etc.)</h3>



<p class="wp-block-paragraph">As previously announced, we confirmed that the suspicious installer, when executed, <strong>downloads additional files from external domains and executes them</strong>.</p>



<p class="wp-block-paragraph">While we previously confirmed access to <code>emeditorjp[.]com</code>, subsequent investigation has found additional access to <strong><code>emeditorde[.]com</code>, <code>emeditorgb[.]com</code>, and <code>emeditorsb[.]com</code></strong> as well.</p>



<p class="wp-block-paragraph">None of these four domains (<code>emeditorjp[.]com</code>, <code>emeditorde[.]com</code>, <code>emeditorgb[.]com</code>, <code>emeditorsb[.]com</code>) are operated by us (Emurasoft, Inc.).</p>



<p class="wp-block-paragraph">We also confirmed that the PowerShell command described in the previous notice downloads and executes files from external domains, and that this behavior could lead to malware infection and theft of personal information such as passwords.</p>



<p class="wp-block-paragraph">For additional details, please refer to the research report prepared by Mr. Luca Palermo and Mr. Mario Ciccarelli. Mr. Palermo provided the report to us and granted permission for us to publish it, and we would like to express our sincere thanks for their cooperation.</p>



<ul class="wp-block-list">
<li><a href="https://download.emeditor.info/doc/malware_analysis_report_final.pdf" target="_blank" rel="noreferrer noopener">Malware Analysis Report – Multi-stage Infostealer by Luca Palermo and Mario Ciccarelli</a></li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">6. Why This Was “Hard to Spot”</h3>



<p class="wp-block-paragraph">As a basic reality, both <strong>domains</strong> and <strong>digital signatures</strong> can be obtained by third parties under certain conditions.</p>



<ul class="wp-block-list">
<li>Domains can often be purchased at low cost if they are unused or not renewed.</li>



<li>Code-signing certificates can generally be obtained from many certificate authorities (in this case, the issuer was Microsoft).</li>



<li>Once an issue is discovered, the main available response is to contact the issuer/certification authority and request revocation.</li>
</ul>



<p class="wp-block-paragraph">From a technical perspective, <strong>MSI installers</strong> can include arbitrary scripts (including PowerShell) via custom actions. With sufficient knowledge, an attacker can inject a malware loader into an installer that closely resembles a legitimate, widely distributed one.</p>



<p class="wp-block-paragraph">Even if the installer were an EXE rather than an MSI, similar attacks would still be possible.</p>



<p class="wp-block-paragraph">Unfortunately, this means it is difficult for software companies to completely prevent malicious installers that closely imitate legitimate ones from being created and distributed. We must assume that similarly sophisticated, multi-stage malware installers could appear again in the future.</p>



<p class="wp-block-paragraph">That said, we believe the core issues in this incident can be summarized as follows:</p>



<ol class="wp-block-list">
<li>A convenient <strong>redirect (download path)</strong> used on our website was altered without being detected.</li>



<li>A <strong>malicious installer</strong> was placed on our website by an external party.</li>
</ol>



<p class="wp-block-paragraph">Because these occurred together, we take full responsibility for the fact that customers were harmed after downloading from our official website, and we will reflect this in our future preventive measures.</p>



<h4 class="wp-block-heading">6-1. Malicious files placed on the EmEditor website</h4>



<p class="wp-block-paragraph">In addition to the malicious installer <code>emed64_25.4.3.msi</code>, we discovered a file named <code>base64.php</code> under a plugin directory. After analyzing <code>base64.php</code>, we determined it was a typical backdoor (remote code execution / RCE).</p>



<p class="wp-block-paragraph">We also found that a script had been added to <code>footer.php</code> (within the WordPress theme directory). This script hijacked clicks intended for the legitimate URL:</p>



<ul class="wp-block-list">
<li><code>https://support.emeditor.com/ja/downloads/latest/installer/64</code></li>
</ul>



<p class="wp-block-paragraph">and redirected them to:</p>



<ul class="wp-block-list">
<li><code>/wp-content/uploads/filebase/emeditor-core/emed64_25.4.3.msi</code></li>
</ul>



<p class="wp-block-paragraph">As a result, clicking the “Download Now” button on the homepage could lead to the malicious file being downloaded.</p>



<p class="wp-block-paragraph">More maliciously, the script was configured to trigger <strong>only for visitors who were not logged in</strong>, making the issue difficult for administrators to reproduce and detect. As a result, even when we checked the site ourselves, we did not immediately notice that the redirect had been altered.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">7. Cause (Current Assessment)</h3>



<p class="wp-block-paragraph">We are still investigating and have not reached a final conclusion. However, we are considering the possibilities below.</p>



<p class="wp-block-paragraph">WordPress is made up of multiple components—core, plugins, themes, and more—maintained by many developers. Vulnerabilities are regularly discovered in these components, and updates are released over time.</p>



<p class="wp-block-paragraph">We regularly update plugins and themes, but in some cases vulnerabilities may remain unpatched for extended periods. It is possible that the attack exploited such a vulnerability.</p>



<p class="wp-block-paragraph">It is also possible that the SFTP account in use was targeted.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">8. Our Response (Completed / Planned)</h3>



<p class="wp-block-paragraph">We immediately deleted the malicious file <code>emed64_25.4.3.msi</code>. We also reviewed file modification logs and confirmed the addition of <code>base64[.]php</code> and changes to <code>footer[.]php</code>. After identifying <code>base64[.]php</code> as a backdoor, we scanned the entire site.</p>



<p class="wp-block-paragraph">We then rebuilt the website, reinstalled all plugins, and removed unnecessary plugins. We also scanned internal computers and changed login passwords for all WordPress sites and related services. We audited several services we used by looking through their logs.</p>



<p class="wp-block-paragraph">In addition, we stopped using redirects for download buttons such as “Download Now,” and replaced them <strong>with direct links to verified safe files</strong>. We also updated the download page to clearly show the MSI’s <strong>SHA-256</strong> and added instructions encouraging users to <strong>verify the digital signature</strong>.</p>



<p class="wp-block-paragraph">To further strengthen the EmEditor homepage download path, we are also considering <strong>migrating the site to a custom/static website instead of WordPress</strong> in the near future.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">9. Closing</h3>



<p class="wp-block-paragraph">As described above, an installer that has been tampered with can perform extremely dangerous actions when executed. At the same time, we cannot fundamentally prevent third parties from creating and distributing malicious installers that imitate legitimate ones.</p>



<p class="wp-block-paragraph">Therefore, <strong>our top priority is to make sure no one can obtain malware through our website, since it’s our primary distribution channel.</strong></p>



<p class="wp-block-paragraph">This incident also reminded us that while popular CMS platforms such as Xoops and WordPress are convenient, their extensibility can increase exposure to vulnerabilities—and that simply keeping plugins and themes updated does not eliminate risk entirely.</p>



<p class="wp-block-paragraph">Fortunately, the <strong><a href="https://support.emeditor.com/en/" target="_blank" rel="noreferrer noopener">Emurasoft Customer Center</a> was not compromised, and our database remained secure. We have no evidence that anyone accessed our customer database.</strong></p>



<p class="wp-block-paragraph">In the hope that what we learned from this incident will help other software companies, we have included as much detail and context as possible rather than limiting this to a brief report.</p>



<p class="wp-block-paragraph">We once again offer our sincere apologies for the concern and inconvenience caused. We especially apologize to those who suffered harm related to infection.</p>



<p class="wp-block-paragraph">Thank you for your continued support of EmEditor.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>[Important] Security Incident Notice Regarding the EmEditor Installer Download Link</title>
		<link>/general/important-security-incident-notice-regarding-the-emeditor-installer-download-link/</link>
		
		<dc:creator><![CDATA[Yutaka Emura]]></dc:creator>
		<pubDate>Tue, 23 Dec 2025 01:36:40 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[incident]]></category>
		<category><![CDATA[website]]></category>
		<guid isPermaLink="false">https://www.emeditor.com/?p=30514</guid>

					<description><![CDATA[We regret to inform you that we have identified an incident involving the EmEditor official website’s download path (the [Download Now] button), where unauthorized modification by a third party is suspected. During the affected period, the installer downloaded via that button may not have been the legitimate file provided by us (Emurasoft, Inc.). We sincerely [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">We regret to inform you that we have identified an incident involving the EmEditor official website’s download path (the <strong>[Download Now]</strong> button), where <strong>unauthorized modification by a third party is suspected</strong>. During the affected period, the installer downloaded via that button may not have been the legitimate file provided by us (Emurasoft, Inc.).</p>



<p class="wp-block-paragraph">We sincerely apologize for the concern and inconvenience this may cause. Please review the information below.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">1. Potentially Affected Period</h3>



<ul class="wp-block-list">
<li><strong>Dec 19, 2025 18:39 – Dec 22, 2025 12:50 (U.S. Pacific Time)</strong></li>
</ul>



<p class="wp-block-paragraph">If you downloaded the installer from the <strong>[Download Now]</strong> button on the EmEditor homepage during this period, it is possible that a <strong>different file without our digital signature</strong> was downloaded. This is a conservative estimate, and in reality the affected period may have been narrower and limited to a specific timeframe.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">2. Incident Summary (High-Level Cause)</h3>



<p class="wp-block-paragraph">The <strong>[Download Now]</strong> button normally points to the following URL:</p>



<ul class="wp-block-list">
<li>https://support.emeditor.com/en/downloads/latest/installer/64</li>
</ul>



<p class="wp-block-paragraph">This URL uses a redirect. However, during the affected period, the <strong>redirect settings appear to have been altered by a third party</strong>, resulting in downloads being served from the following (incorrect) URL:</p>



<ul class="wp-block-list">
<li>&#8230;/uploads/filebase/emeditor-core/emed64_25.4.3.msi</li>
</ul>



<p class="wp-block-paragraph">This file was not created by Emurasoft, Inc., and it has <strong>already been removed</strong>.</p>



<p class="wp-block-paragraph">As a result, we have confirmed that the downloaded file may be digitally signed not by us, but by another organization named <strong>WALSHAM INVESTMENTS LIMITED</strong>.</p>



<p class="wp-block-paragraph"><em>Note: This issue may not be limited to the English page and may affect similar URLs for other languages as well (including Japanese).</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">3. File Confirmed as Potentially Affected</h3>



<p class="wp-block-paragraph">At this time, the only file confirmed to be involved is:</p>



<ul class="wp-block-list">
<li><strong>emed64_25.4.3.msi</strong></li>
</ul>



<h4 class="wp-block-heading">Legitimate file (official)</h4>



<ul class="wp-block-list">
<li>File name: <strong>emed64_25.4.3.msi</strong></li>



<li>Size: <strong>80,376,832 bytes</strong></li>



<li>Digital signature: <strong>Emurasoft, Inc.</strong></li>



<li><strong>SHA-256:</strong> <code>e5f9c1e9b586b59712cefa834b67f829ccbed183c6855040e6d42f0c0c3fcb3e</code></li>
</ul>



<h4 class="wp-block-heading">Suspicious file (possible tampering)</h4>



<ul class="wp-block-list">
<li>File name: <strong>emed64_25.4.3.msi</strong></li>



<li>Size: <strong>80,380,416 bytes</strong></li>



<li>Digital signature: <strong>WALSHAM INVESTMENTS LIMITED</strong></li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">4. Not Affected</h3>



<p class="wp-block-paragraph">You are <strong>not affected</strong> if any of the following applies:</p>



<ul class="wp-block-list">
<li>You updated via EmEditor’s <strong>Update Checker</strong> or through EmEditor’s automatic update</li>



<li>You downloaded directly from <code>download.emeditor.info</code><br>Example: https://download.emeditor.info/emed64_25.4.3.msi</li>



<li>You downloaded a file <strong>other than</strong> <code>emed64_25.4.3.msi</code></li>



<li>You used the <strong>portable version</strong></li>



<li>You used the <strong>store app version</strong></li>



<li>You installed/updated using <strong>winget</strong></li>



<li>You downloaded the file but <strong>did not run/execute it</strong></li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">5. How to Check and What to Do</h3>



<p class="wp-block-paragraph">If you may have downloaded the installer via <strong>[Download Now]</strong> during the affected period, please verify the <strong>digital signature</strong> and <strong>SHA-256 hash</strong> of the file <code>emed64_25.4.3.msi</code>.</p>



<h4 class="wp-block-heading">5-1. How to check the Digital Signature (Windows)</h4>



<ol class="wp-block-list">
<li>Right-click the file (<code>emed64_25.4.3.msi</code>) and select <strong>Properties</strong>.</li>



<li>Open the <strong>Digital Signatures</strong> tab.</li>



<li>Confirm that the signer is <strong>Emurasoft, Inc.</strong></li>
</ol>



<ul class="wp-block-list">
<li>If it shows <strong>WALSHAM INVESTMENTS LIMITED</strong>, the file may be malicious.</li>
</ul>



<p class="wp-block-paragraph"><em>If the “Digital Signatures” tab is not shown, the file may be unsigned or the signature may not be recognized. In that case, do not run the file; delete it and follow the guidance below.</em></p>



<h4 class="wp-block-heading">5-2. How to check SHA-256 (Windows / PowerShell)</h4>



<p class="wp-block-paragraph">Open PowerShell and run:</p>



<pre class="wp-block-code"><code>Get-FileHash .\emed64_25.4.3.msi -Algorithm SHA256</code></pre>



<p class="wp-block-paragraph">Confirm the output SHA-256 matches:</p>



<ul class="wp-block-list">
<li>Legitimate SHA-256: <br><code>e5f9c1e9b586b59712cefa834b67f829ccbed183c6855040e6d42f0c0c3fcb3e</code></li>
</ul>



<h4 class="wp-block-heading">If the signature or SHA-256 does not match (Recommended actions)</h4>



<p class="wp-block-paragraph">If the digital signature is not <strong>Emurasoft, Inc.</strong> (e.g., it is <strong>WALSHAM INVESTMENTS LIMITED</strong>) or the SHA-256 does not match, you may have obtained a tampered file (potentially containing malware).</p>



<ul class="wp-block-list">
<li>Immediately <strong>disconnect the affected computer from the network</strong> (wired/wireless)</li>



<li>Run a full <strong>malware scan</strong> on the system</li>



<li>Depending on the situation, consider <strong>refreshing/rebuilding the environment including the OS</strong></li>



<li>Consider the possibility of credential exposure and <strong>change passwords</strong> used/stored on that device (and enable MFA where possible)</li>
</ul>



<p class="wp-block-paragraph"><em>If you are using EmEditor in an organization, we also recommend contacting your internal security team (e.g., CSIRT) and preserving relevant logs where possible.</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">6. Observed Behavior (As Currently Confirmed)</h3>



<p class="wp-block-paragraph">The suspicious installer may attempt to run a powershell script, which downloads and executes content from <code>emeditorjp[.]com</code>.<br><strong>emeditorjp[.]com is not a domain managed by Emurasoft, Inc.</strong></p>



<p class="wp-block-paragraph">Please also note that the installer may <strong>still proceed to install EmEditor normally and install legitimate EmEditor program files</strong>, which could make the issue difficult to notice.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">7. Current Status and Next Updates</h3>



<p class="wp-block-paragraph">We are continuing to investigate the facts and determine the full scope of impact. We will provide updates on this page and/or through our official channels as soon as more information becomes available.<br>We take this incident very seriously and will implement necessary measures to identify the cause and prevent recurrence.</p>



<p class="wp-block-paragraph">We sincerely apologize again for the inconvenience and concern this may have caused, and we appreciate your understanding and continued support of EmEditor.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Interview article with an Internet Watch editor was published today!</title>
		<link>/reviews/interview-article-with-an-internet-watch-editor-was-published-today/</link>
		
		<dc:creator><![CDATA[Yutaka Emura]]></dc:creator>
		<pubDate>Mon, 03 Feb 2020 16:45:53 +0000</pubDate>
				<category><![CDATA[Reviews]]></category>
		<category><![CDATA[website]]></category>
		<guid isPermaLink="false">https://www.emeditor.com/?p=26559</guid>

					<description><![CDATA[Internet Watch (Japanese): Commitment to &#8220;edit text&#8221;! Why is the de facto standard editor &#8220;EmEditor&#8221; different from other editors?]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><a href="https://internet.watch.impress.co.jp/docs/interview/1231545.html">Internet Watch (Japanese): Commitment to &#8220;edit text&#8221;! Why is the de facto standard editor &#8220;EmEditor&#8221; different from other editors?</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Interview article with a MyNavi News editor was published today!</title>
		<link>/reviews/interview-article-with-a-mynavi-news-editor-was-published-today/</link>
		
		<dc:creator><![CDATA[Yutaka Emura]]></dc:creator>
		<pubDate>Mon, 03 Feb 2020 16:42:38 +0000</pubDate>
				<category><![CDATA[Reviews]]></category>
		<category><![CDATA[website]]></category>
		<guid isPermaLink="false">https://www.emeditor.com/?p=26558</guid>

					<description><![CDATA[MyNavi News: Approaching the true value of EmEditor, a text editor that continues to be comfortable and fast &#8211; Interview with Yutaka Emura, President of Emurasoft, Inc. (Japanese)]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><a href="https://news.mynavi.jp/kikaku/20200203-964022/">MyNavi News: Approaching the true value of EmEditor, a text editor that continues to be comfortable and fast &#8211; Interview with Yutaka Emura, President of Emurasoft, Inc. (Japanese)</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The 64-bit portable version released. File hosting switched to the Amazon S3 cloud</title>
		<link>/general/64-bit-portable-version-released-file-hosting-switched-amazon-s3-cloud/</link>
					<comments>/general/64-bit-portable-version-released-file-hosting-switched-amazon-s3-cloud/#respond</comments>
		
		<dc:creator><![CDATA[Yutaka Emura]]></dc:creator>
		<pubDate>Tue, 03 Feb 2015 20:13:18 +0000</pubDate>
				<category><![CDATA[General]]></category>
		<category><![CDATA[portable]]></category>
		<category><![CDATA[website]]></category>
		<guid isPermaLink="false">https://www.emeditor.com/?p=19819</guid>

					<description><![CDATA[Today, we released EmEditor v14.8.0, and we also released the 64-bit version of the portable version, in addition to the installer and 32-bit portable versions today. All the installers of all the formats are available to download at the Download page. Moreover, the file hosting was switched from the old web hosting server to the [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>Today, we released EmEditor v14.8.0, and we also released the 64-bit version of the portable version, in addition to the installer and 32-bit portable versions today. All the installers of all the formats are available to download at the <a title="Download" href="/download/">Download page</a>.</p>
<p>Moreover, the file hosting was switched from the old web hosting server to the Amazon S3 cloud service. We hope this change will bring us faster and more stable downloads and updates.</p>
<p>We will continue improving our services. Please contact us if there are any issues with downloading or updating.</p>
<p>Thank you for using EmEditor!</p>
]]></content:encoded>
					
					<wfw:commentRss>/general/64-bit-portable-version-released-file-hosting-switched-amazon-s3-cloud/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Version 14.6 feature page was added</title>
		<link>/emeditor-core/version-14-6-feature-page-was-added/</link>
					<comments>/emeditor-core/version-14-6-feature-page-was-added/#respond</comments>
		
		<dc:creator><![CDATA[Yutaka Emura]]></dc:creator>
		<pubDate>Sat, 18 Oct 2014 01:23:23 +0000</pubDate>
				<category><![CDATA[EmEditor Core]]></category>
		<category><![CDATA[v14]]></category>
		<category><![CDATA[website]]></category>
		<guid isPermaLink="false">https://www.emeditor.com/?p=19485</guid>

					<description><![CDATA[Today, we added the EmEditor Version 14.6 feature page. This new version adds important features with big data and database files in mind: more CSV support, Filter Bar, more Search options including the Extract button. We are planning to release EmEditor Version 14.6 very soon. Thank you for using EmEditor!]]></description>
										<content:encoded><![CDATA[<p>Today, we added the <a href="/text-editor-features/history/new-version-14-6/"><strong>EmEditor Version 14.6 feature</strong> page</a>. This new version adds important features with <strong>big data</strong> and <strong>database files</strong> in mind: more <strong>CSV</strong> support, <strong>Filter Bar</strong>, more <strong>Search</strong> options including the <strong>Extract</strong> button. We are planning to release EmEditor Version 14.6 very soon.</p>
<p>Thank you for using EmEditor!</p>
]]></content:encoded>
					
					<wfw:commentRss>/emeditor-core/version-14-6-feature-page-was-added/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
