Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. They finally did it.

They finally did it.

Scheduled Pinned Locked Moved Uncategorized
noaimicroslopmicrosoftwindowsprogramming
42 Posts 36 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • pheonix@hachyderm.ioP pheonix@hachyderm.io

    They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

    This CVE is an 8.8 severity RCE in Notepad of all things lmao.

    Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

    We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

    Security Update Guide - Microsoft Security Response Center

    favicon

    (msrc.microsoft.com)

    #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

    Link Preview Image
    hermannus@stegodon.nlH This user is from outside of this forum
    hermannus@stegodon.nlH This user is from outside of this forum
    hermannus@stegodon.nl
    wrote last edited by
    #5

    @pheonix youth is skipping to old nokia's, to dvd's, to buying vinyl and even to lending in videostores (really!).
    So how do companies keep adding more and more features nobody wants anymore?

    1 Reply Last reply
    0
    • pheonix@hachyderm.ioP pheonix@hachyderm.io

      They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

      This CVE is an 8.8 severity RCE in Notepad of all things lmao.

      Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

      We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

      Security Update Guide - Microsoft Security Response Center

      favicon

      (msrc.microsoft.com)

      #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

      Link Preview Image
      bsm@swiss.socialB This user is from outside of this forum
      bsm@swiss.socialB This user is from outside of this forum
      bsm@swiss.social
      wrote last edited by
      #6

      @pheonix

      One of the reasons, why I use Notepad++ (https://notepad-plus-plus.org/downloads/)

      C 1 Reply Last reply
      0
      • bsm@swiss.socialB bsm@swiss.social

        @pheonix

        One of the reasons, why I use Notepad++ (https://notepad-plus-plus.org/downloads/)

        C This user is from outside of this forum
        C This user is from outside of this forum
        clickymcticker@hachyderm.io
        wrote last edited by
        #7

        @bsm @pheonix Oh, did you not hear?

        Link Preview Image
        Notepad++ users take note: It's time to check if you're hacked

        Suspected China-state hackers used update infrastructure to deliver backdoored version.

        favicon

        Ars Technica (arstechnica.com)

        bsm@swiss.socialB 1 Reply Last reply
        0
        • pheonix@hachyderm.ioP pheonix@hachyderm.io

          They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

          This CVE is an 8.8 severity RCE in Notepad of all things lmao.

          Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

          We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

          Security Update Guide - Microsoft Security Response Center

          favicon

          (msrc.microsoft.com)

          #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

          Link Preview Image
          13reak@infosec.exchange1 This user is from outside of this forum
          13reak@infosec.exchange1 This user is from outside of this forum
          13reak@infosec.exchange
          wrote last edited by
          #8

          @pheonix

          I'm not surprised...

          A simple cat <file> on the command line can also compromise your system. If you're unsure, you should therefore use cat -v <file> when I'm not mistaken.

          1 Reply Last reply
          1
          0
          • R relay@relay.infosec.exchange shared this topic
          • C clickymcticker@hachyderm.io

            @bsm @pheonix Oh, did you not hear?

            Link Preview Image
            Notepad++ users take note: It's time to check if you're hacked

            Suspected China-state hackers used update infrastructure to deliver backdoored version.

            favicon

            Ars Technica (arstechnica.com)

            bsm@swiss.socialB This user is from outside of this forum
            bsm@swiss.socialB This user is from outside of this forum
            bsm@swiss.social
            wrote last edited by
            #9

            @ClickyMcTicker @pheonix There is no problem with it with the newest version 8.9.1

            stiiin@infosec.spaceS 1 Reply Last reply
            0
            • pheonix@hachyderm.ioP pheonix@hachyderm.io

              They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

              This CVE is an 8.8 severity RCE in Notepad of all things lmao.

              Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

              We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

              Security Update Guide - Microsoft Security Response Center

              favicon

              (msrc.microsoft.com)

              #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

              Link Preview Image
              di4na@hachyderm.ioD This user is from outside of this forum
              di4na@hachyderm.ioD This user is from outside of this forum
              di4na@hachyderm.io
              wrote last edited by
              #10

              @pheonix nothing can be safe. It is computing. That ship has sailed a loooooong time ago

              1 Reply Last reply
              0
              • pheonix@hachyderm.ioP pheonix@hachyderm.io

                They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                Security Update Guide - Microsoft Security Response Center

                favicon

                (msrc.microsoft.com)

                #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                Link Preview Image
                gabrielesvelto@mas.toG This user is from outside of this forum
                gabrielesvelto@mas.toG This user is from outside of this forum
                gabrielesvelto@mas.to
                wrote last edited by
                #11

                @pheonix *vibe-coding intensifies*

                pheonix@hachyderm.ioP 1 Reply Last reply
                0
                • pheonix@hachyderm.ioP pheonix@hachyderm.io

                  They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                  This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                  Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                  We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                  Security Update Guide - Microsoft Security Response Center

                  favicon

                  (msrc.microsoft.com)

                  #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                  Link Preview Image
                  G This user is from outside of this forum
                  G This user is from outside of this forum
                  grimace1298@defcon.social
                  wrote last edited by
                  #12

                  @pheonix Idk how the fcuk they can mess up a simple notepad application. When you add junk (Copilot) it's kinda expected lol. #microslop f-ing company 🤮

                  1 Reply Last reply
                  0
                  • pheonix@hachyderm.ioP pheonix@hachyderm.io

                    They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                    This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                    Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                    We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                    Security Update Guide - Microsoft Security Response Center

                    favicon

                    (msrc.microsoft.com)

                    #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                    Link Preview Image
                    trillytrill@mastodon.artT This user is from outside of this forum
                    trillytrill@mastodon.artT This user is from outside of this forum
                    trillytrill@mastodon.art
                    wrote last edited by
                    #13

                    @pheonix
                    Notepad?? FRIGGIN NOTEPAD? HOW DO YOU SCREW UP SOMETHING LIKE A BASIC-ASS TEXT EDITOR PROGRAM?

                    mkj@social.mkj.earthM pheonix@hachyderm.ioP 2 Replies Last reply
                    0
                    • pheonix@hachyderm.ioP pheonix@hachyderm.io

                      They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                      This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                      Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                      We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                      Security Update Guide - Microsoft Security Response Center

                      favicon

                      (msrc.microsoft.com)

                      #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                      Link Preview Image
                      vyskocilm@witter.czV This user is from outside of this forum
                      vyskocilm@witter.czV This user is from outside of this forum
                      vyskocilm@witter.cz
                      wrote last edited by
                      #14

                      @pheonix This is the most vibe slop, ever! 😁

                      1 Reply Last reply
                      0
                      • trillytrill@mastodon.artT trillytrill@mastodon.art

                        @pheonix
                        Notepad?? FRIGGIN NOTEPAD? HOW DO YOU SCREW UP SOMETHING LIKE A BASIC-ASS TEXT EDITOR PROGRAM?

                        mkj@social.mkj.earthM This user is from outside of this forum
                        mkj@social.mkj.earthM This user is from outside of this forum
                        mkj@social.mkj.earth
                        wrote last edited by
                        #15

                        "How do you screw up [friggin Notepad]?"

                        Gradually, and then suddenly.

                        I think.

                        @trillytrill @pheonix

                        1 Reply Last reply
                        1
                        0
                        • R relay@relay.mycrowd.ca shared this topic
                        • bsm@swiss.socialB bsm@swiss.social

                          @ClickyMcTicker @pheonix There is no problem with it with the newest version 8.9.1

                          stiiin@infosec.spaceS This user is from outside of this forum
                          stiiin@infosec.spaceS This user is from outside of this forum
                          stiiin@infosec.space
                          wrote last edited by
                          #16

                          @bsm @ClickyMcTicker @pheonix Yet

                          1 Reply Last reply
                          0
                          • pheonix@hachyderm.ioP pheonix@hachyderm.io

                            They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                            This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                            Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                            We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                            Security Update Guide - Microsoft Security Response Center

                            favicon

                            (msrc.microsoft.com)

                            #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                            Link Preview Image
                            bdf2121cc3334b35b6ecda66e471@mastodon.socialB This user is from outside of this forum
                            bdf2121cc3334b35b6ecda66e471@mastodon.socialB This user is from outside of this forum
                            bdf2121cc3334b35b6ecda66e471@mastodon.social
                            wrote last edited by
                            #17

                            @pheonix Nothing from Microsoft, no.

                            1 Reply Last reply
                            0
                            • pheonix@hachyderm.ioP pheonix@hachyderm.io

                              They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                              This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                              Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                              We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                              Security Update Guide - Microsoft Security Response Center

                              favicon

                              (msrc.microsoft.com)

                              #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                              Link Preview Image
                              murenius@chaos.socialM This user is from outside of this forum
                              murenius@chaos.socialM This user is from outside of this forum
                              murenius@chaos.social
                              wrote last edited by
                              #18

                              @pheonix That's what you get for using AI in development. What could possibly go wrong?

                              pheonix@hachyderm.ioP 1 Reply Last reply
                              0
                              • pheonix@hachyderm.ioP pheonix@hachyderm.io

                                They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                Security Update Guide - Microsoft Security Response Center

                                favicon

                                (msrc.microsoft.com)

                                #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                Link Preview Image
                                naahrathescaled@furry.engineerN This user is from outside of this forum
                                naahrathescaled@furry.engineerN This user is from outside of this forum
                                naahrathescaled@furry.engineer
                                wrote last edited by
                                #19

                                @pheonix How can you fuckup Markdown support so hard

                                1 Reply Last reply
                                0
                                • pheonix@hachyderm.ioP pheonix@hachyderm.io

                                  They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                  This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                  Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                  We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                  Security Update Guide - Microsoft Security Response Center

                                  favicon

                                  (msrc.microsoft.com)

                                  #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                  Link Preview Image
                                  tiikerikani@dice.campT This user is from outside of this forum
                                  tiikerikani@dice.campT This user is from outside of this forum
                                  tiikerikani@dice.camp
                                  wrote last edited by
                                  #20

                                  @pheonix
                                  STOP UPDATING NOTEPAD

                                  (source: https://www.reddit.com/r/windowsmemes/comments/1plqsi2/stop_updating_notepad/)

                                  Link Preview Image
                                  1 Reply Last reply
                                  0
                                  • pheonix@hachyderm.ioP pheonix@hachyderm.io

                                    They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                    This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                    Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                    We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                    Security Update Guide - Microsoft Security Response Center

                                    favicon

                                    (msrc.microsoft.com)

                                    #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                    Link Preview Image
                                    bluszcz@mastodon.com.plB This user is from outside of this forum
                                    bluszcz@mastodon.com.plB This user is from outside of this forum
                                    bluszcz@mastodon.com.pl
                                    wrote last edited by
                                    #21

                                    @pheonix

                                    not the first one, not the last one 😄

                                    CVE-2019-12735 CVE-2002-1377 CVE-2016-1248 CVE-2021-43908 CVE-2023-36742 CVE-2020-27955 CVE-2007-5795 CVE-2022-48337 CVE-2024-25255 CVE-2025-49144 (

                                    pheonix@hachyderm.ioP 1 Reply Last reply
                                    0
                                    • pheonix@hachyderm.ioP pheonix@hachyderm.io

                                      They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                      This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                      Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                      We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                      Security Update Guide - Microsoft Security Response Center

                                      favicon

                                      (msrc.microsoft.com)

                                      #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                      Link Preview Image
                                      bolomkxxviii@mastodon.socialB This user is from outside of this forum
                                      bolomkxxviii@mastodon.socialB This user is from outside of this forum
                                      bolomkxxviii@mastodon.social
                                      wrote last edited by
                                      #22

                                      @pheonix MicroSlop CraPilot.

                                      1 Reply Last reply
                                      0
                                      • pheonix@hachyderm.ioP pheonix@hachyderm.io

                                        They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                        This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                        Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                        We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                        Security Update Guide - Microsoft Security Response Center

                                        favicon

                                        (msrc.microsoft.com)

                                        #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                        Link Preview Image
                                        mihamarkic@mastodon.socialM This user is from outside of this forum
                                        mihamarkic@mastodon.socialM This user is from outside of this forum
                                        mihamarkic@mastodon.social
                                        wrote last edited by
                                        #23

                                        @pheonix what's an unverified protocol?

                                        1 Reply Last reply
                                        0
                                        • avuko@infosec.exchangeA This user is from outside of this forum
                                          avuko@infosec.exchangeA This user is from outside of this forum
                                          avuko@infosec.exchange
                                          wrote last edited by
                                          #24

                                          @jkb @pheonix That seems to be the case, although the weakness is in Microsoft Notepad incorrectly handling “an unverified protocol”, not in something the user then has to do or interact with. Besides clicking a link.

                                          This reads to me like an URI protocol handling issue.

                                          And that functionality is not something they’d have to reinvent or vibe code.

                                          You know, with their proprietary plain text editor running on their proprietary OS, and next to their proprietary file explorer, their proprietary internet browser, their proprietary email client and proprietary network agents.

                                          All their proprietary software handling URI protocols… RIGHT THERE.

                                          jkb@gotosocial.jkbockstael.beJ 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups