So Notepad++ had a security SNAFU which puts them in a very large group of FOSS and corporate software providers.
Taking 6 months to identify and resolve the attack is not nice, but by the looks of things this was quite a well resourced attack against a limited resources provider. It is also not unique for vulnerabilities and exploits to go undetected for quite a long time - the trade press is repeatedly covering them. And, this is not just a FOSS problem - it affects corporate software as well. In some ways the corporate software can be more problematic if the corporation spends more time and effort denying and obfuscating the problem because it will have an adverse impact on profits (reduced sales, having to pay the engineering staff to fix the problem and pay customer services to field more support calls)
This is a supply chain attack and the underlying problem is quite challenging. The solution is not going to be to axe small players for any lapse in a complex and adversarial field of IT (I am pretty sure you will not be axing Microsoft after the next security SNAFU - it will simply be another Patch Tuesday).
This Helldesk AC sounds like the sort of complete tosser (because of their unnecessary pile-in on Notepad++) that makes me glad I am out of the corporate hell where IT Support is all about sucking up to the Executives with personal service while the masses get a shoddy service; particularly if they happen to be in Engineering and are trying to use their computer as a tool to do engineering rather than simply generate Powerpoint presentations. No consideration of why Notepad++ was on the whitelist, or what the impact of removing it will be (beyond the it makes it somebody else's problem, not ours). Yes - there might have been a need to have an immediate response- but if you have already been hit, taking out Notepad++ now would still seem to leave you with an infection problem to sort out, and you still have a problem with everything else that is on your whitelist - so this is no solution. But something must be done, and this is something.
FFS - February has got off to a depressing start. The only good news (for me) is that I had auto-update deactivated so I am running old versions of Notepad++ and avoided the troublesome period. I guess I can look forward to seeing all the improvements to Notepad++ when I install the new 'secure' version. Keep up the good work guys and ignore the loud-mouthed tossers.