Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

  1. Home
  2. Uncategorized
  3. They finally did it.

They finally did it.

Geplant Angeheftet Gesperrt Verschoben Uncategorized
noaimicroslopmicrosoftwindowsprogrammingwritingwindows11enshittificationcybersecurityinfosec
68 Beiträge 50 Kommentatoren 1 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • pheonix@hachyderm.ioP pheonix@hachyderm.io

    They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

    This CVE is an 8.8 severity RCE in Notepad of all things lmao.

    Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

    We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

    #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

    codemonkeymike@fosstodon.orgC This user is from outside of this forum
    codemonkeymike@fosstodon.orgC This user is from outside of this forum
    codemonkeymike@fosstodon.org
    schrieb zuletzt editiert von
    #61

    @pheonix

    1 Antwort Letzte Antwort
    0
    • pheonix@hachyderm.ioP pheonix@hachyderm.io

      They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

      This CVE is an 8.8 severity RCE in Notepad of all things lmao.

      Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

      We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

      https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

      #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

      hp@mastodon.tmm.cxH This user is from outside of this forum
      hp@mastodon.tmm.cxH This user is from outside of this forum
      hp@mastodon.tmm.cx
      schrieb zuletzt editiert von
      #62

      @pheonix how are they making the same mistakes in their products since their first email client in the 90s.

      Every... Fucking... Time...

      How

      1 Antwort Letzte Antwort
      0
      • naahrathescaled@furry.engineerN naahrathescaled@furry.engineer

        @pheonix How can you fuckup Markdown support so hard

        drwho@masto.hackers.townD This user is from outside of this forum
        drwho@masto.hackers.townD This user is from outside of this forum
        drwho@masto.hackers.town
        schrieb zuletzt editiert von
        #63

        @pheonix @NaahraTheScaled Microsoft: "Challenge accepted."

        1 Antwort Letzte Antwort
        0
        • mkoek@mastodon.nlM mkoek@mastodon.nl

          @pheonix oh wow, is it real? Saw it this morning and thought it was a joke.

          drwho@masto.hackers.townD This user is from outside of this forum
          drwho@masto.hackers.townD This user is from outside of this forum
          drwho@masto.hackers.town
          schrieb zuletzt editiert von
          #64

          @pheonix @mkoek It is.

          Wish it was a fever dream.

          1 Antwort Letzte Antwort
          0
          • pheonix@hachyderm.ioP pheonix@hachyderm.io

            They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

            This CVE is an 8.8 severity RCE in Notepad of all things lmao.

            Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

            We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

            https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

            #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

            musevg@23.socialM This user is from outside of this forum
            musevg@23.socialM This user is from outside of this forum
            musevg@23.social
            schrieb zuletzt editiert von
            #65

            @pheonix
            I'm old enough to remember how @adamshostack re-invented application security at Microsoft and basically for most of the industry. Holy $#!+ how the times have changed 😞

            1 Antwort Letzte Antwort
            0
            • cybso@osna.socialC cybso@osna.social

              @pheonix vibe coder doing vibe coding things 🤷‍♂️

              musevg@23.socialM This user is from outside of this forum
              musevg@23.socialM This user is from outside of this forum
              musevg@23.social
              schrieb zuletzt editiert von
              #66

              @pheonix @cybso
              30 per cent AI code! FTW!

              1 Antwort Letzte Antwort
              0
              • pheonix@hachyderm.ioP pheonix@hachyderm.io

                They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                S This user is from outside of this forum
                S This user is from outside of this forum
                spacelifeform@infosec.exchange
                schrieb zuletzt editiert von
                #67

                @pheonix

                It is Windows, there is a suprise inside every time you open the box.

                #CrackerJack

                1 Antwort Letzte Antwort
                0
                • fabio@manganiello.euF fabio@manganiello.eu

                  @pheonix@hachyderm.io the thing is that there are many, many safe existing libraries to properly render and parse #Markdown without exposing yourself to RCE.

                  But my guess is that some project manager at #Microsoft simply went like "nah, I don't want to wrestle with those licensing issues - just implement a Markdown parser/renderer from scratch, specifically tailored for all the legacy code we have in Notepad, with this over-stretched team of 3 contractors, and get it done by the end of the quarter".

                  jc0f0116@infosec.exchangeJ This user is from outside of this forum
                  jc0f0116@infosec.exchangeJ This user is from outside of this forum
                  jc0f0116@infosec.exchange
                  schrieb zuletzt editiert von
                  #68

                  @fabio @pheonix It's not a renderer issue. It doesn't pop up a warning before opening certain URL schemes when you ctrl+click on them. Is this an issue? I don't know, conceivably but not in most Windows 11 configuration ("default" isn't really a thing). you can get a t shirt for reporting things like this if you find that interesting😂

                  1 Antwort Letzte Antwort
                  0
                  • mindtunes@troet.cafeM mindtunes@troet.cafe shared this topic
                  Antworten
                  • In einem neuen Thema antworten
                  Anmelden zum Antworten
                  • Älteste zuerst
                  • Neuste zuerst
                  • Meiste Stimmen



                  Copyright (c) 2025 abSpecktrum (@abspecklog@fedimonster.de)

                  Erstellt mit Schlaflosigkeit, Kaffee, Brokkoli & ♥

                  Impressum | Datenschutzerklärung | Nutzungsbedingungen

                  • Anmelden

                  • Du hast noch kein Konto? Registrieren

                  • Anmelden oder registrieren, um zu suchen
                  • Erster Beitrag
                    Letzter Beitrag
                  0
                  • Home
                  • Aktuell
                  • Tags
                  • Über dieses Forum