Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Darkly)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. Uncategorized
  3. They finally did it.

They finally did it.

Scheduled Pinned Locked Moved Uncategorized
noaimicroslopmicrosoftwindowsprogramming
46 Posts 40 Posters 25 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Windy cityP Windy city

    They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

    This CVE is an 8.8 severity RCE in Notepad of all things lmao.

    Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

    We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

    #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

    Miha MarkičM This user is from outside of this forum
    Miha MarkičM This user is from outside of this forum
    Miha Markič
    wrote last edited by
    #23

    @pheonix what's an unverified protocol?

    1 Reply Last reply
    0
    • ⠠⠵ avukoA This user is from outside of this forum
      ⠠⠵ avukoA This user is from outside of this forum
      ⠠⠵ avuko
      wrote last edited by
      #24

      @jkb @pheonix That seems to be the case, although the weakness is in Microsoft Notepad incorrectly handling “an unverified protocol”, not in something the user then has to do or interact with. Besides clicking a link.

      This reads to me like an URI protocol handling issue.

      And that functionality is not something they’d have to reinvent or vibe code.

      You know, with their proprietary plain text editor running on their proprietary OS, and next to their proprietary file explorer, their proprietary internet browser, their proprietary email client and proprietary network agents.

      All their proprietary software handling URI protocols… RIGHT THERE.

      JKBJ 1 Reply Last reply
      0
      • trillytrillT trillytrill

        @pheonix
        Notepad?? FRIGGIN NOTEPAD? HOW DO YOU SCREW UP SOMETHING LIKE A BASIC-ASS TEXT EDITOR PROGRAM?

        Windy cityP This user is from outside of this forum
        Windy cityP This user is from outside of this forum
        Windy city
        wrote last edited by
        #25

        @trillytrill I know, right? It takes a special kind of engineering effort to turn a tool meant for shopping lists into *this*. We've reached the final boss of over-engineering! 🌸✨

        1 Reply Last reply
        0
        • Gabriele SveltoG Gabriele Svelto

          @pheonix *vibe-coding intensifies*

          Windy cityP This user is from outside of this forum
          Windy cityP This user is from outside of this forum
          Windy city
          wrote last edited by
          #26

          @gabrielesvelto The vibes are definitely...high-decibel today. Stay safe out there! 🌊☕

          1 Reply Last reply
          0
          • FandaSinF FandaSin

            @pheonix

            That made me laugh in the morning! Thank you so much!👍😂

            Windy cityP This user is from outside of this forum
            Windy cityP This user is from outside of this forum
            Windy city
            wrote last edited by
            #27

            @FandaSin Laughter is the only logical response to an 8.8 severity rating for Notepad. Glad it brought a smile to your morning! Stay bright! 😊

            1 Reply Last reply
            0
            • Windy cityP This user is from outside of this forum
              Windy cityP This user is from outside of this forum
              Windy city
              wrote last edited by
              #28

              @bluszcz wow

              1 Reply Last reply
              0
              • MureniusM Murenius

                @pheonix That's what you get for using AI in development. What could possibly go wrong?

                Windy cityP This user is from outside of this forum
                Windy cityP This user is from outside of this forum
                Windy city
                wrote last edited by
                #29

                @Murenius but..but AGI?

                1 Reply Last reply
                0
                • Windy cityP Windy city

                  They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                  This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                  Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                  We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                  https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                  #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                  Hasan SarptaşS This user is from outside of this forum
                  Hasan SarptaşS This user is from outside of this forum
                  Hasan Sarptaş
                  wrote last edited by
                  #30

                  @pheonix I never use Notepad for years. I prefer Notepad3 or recently I moved to Zed.

                  https://bsky.app/profile/zed.dev

                  1 Reply Last reply
                  0
                  • Windy cityP Windy city

                    They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                    This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                    Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                    We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                    #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                    Mans RM This user is from outside of this forum
                    Mans RM This user is from outside of this forum
                    Mans R
                    wrote last edited by
                    #31

                    @pheonix You have to click a link. Merely opening the file isn't enough if I'm reading it correctly. That makes it comparable to Internet Explorer back when it would happily download and run any .exe. So pretty stupid.

                    1 Reply Last reply
                    0
                    • BSM (sw.s) 🇨🇭B BSM (sw.s) 🇨🇭

                      @pheonix

                      One of the reasons, why I use Notepad++ (https://notepad-plus-plus.org/downloads/)

                      JamesJ This user is from outside of this forum
                      JamesJ This user is from outside of this forum
                      James
                      wrote last edited by
                      #32

                      @bsm @pheonix

                      Notepad++ is my go-to choice for most everything. Simple, multi-tab app with good cleanup, find-n-replace, and macro tools.

                      1 Reply Last reply
                      0
                      • Windy cityP Windy city

                        They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                        This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                        Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                        We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                        https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                        #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                        ? Offline
                        ? Offline
                        Guest
                        wrote last edited by
                        #33

                        @pheonix No, no it is not. All corporate compute needs to be in the sea.

                        1 Reply Last reply
                        0
                        • Windy cityP Windy city

                          They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                          This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                          Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                          We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                          https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                          #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                          Handler SkylerS This user is from outside of this forum
                          Handler SkylerS This user is from outside of this forum
                          Handler Skyler
                          wrote last edited by
                          #34

                          @pheonix Given that WordPad had that built in, and MS killed it; not surprised

                          1 Reply Last reply
                          0
                          • Windy cityP Windy city

                            They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                            This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                            Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                            We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                            https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                            #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                            Kg. Madee Ⅱ.K This user is from outside of this forum
                            Kg. Madee Ⅱ.K This user is from outside of this forum
                            Kg. Madee Ⅱ.
                            wrote last edited by
                            #35

                            @pheonix and I still think they should have left support for formatted t3xt where it belongs, in Wordpad
                            Notepad could use syntax highlighting & auto-completion maybe ...

                            1 Reply Last reply
                            0
                            • Windy cityP Windy city

                              They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                              This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                              Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                              We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                              https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                              #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                              D This user is from outside of this forum
                              D This user is from outside of this forum
                              DecebalTheThracian
                              wrote last edited by
                              #36

                              @pheonix Windows 11 = ☠️

                              1 Reply Last reply
                              0
                              • Windy cityP Windy city

                                They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                                #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                Don Hawkins - W7DAHD This user is from outside of this forum
                                Don Hawkins - W7DAHD This user is from outside of this forum
                                Don Hawkins - W7DAH
                                wrote last edited by
                                #37

                                @pheonix @duniamelayu Linux?

                                1 Reply Last reply
                                0
                                • Windy cityP Windy city

                                  They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                  This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                  Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                  We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                  https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                                  #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                  GinkgoG This user is from outside of this forum
                                  GinkgoG This user is from outside of this forum
                                  Ginkgo
                                  wrote last edited by
                                  #38

                                  @pheonix Don’t forget that Notepad++ was compromised recently too by state actors… https://notepad-plus-plus.org/news/hijacked-incident-info-update/

                                  1 Reply Last reply
                                  0
                                  • Windy cityP Windy city

                                    They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                    This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                    Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                    We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                                    #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                    FredricT 😷💉🌻🌈F This user is from outside of this forum
                                    FredricT 😷💉🌻🌈F This user is from outside of this forum
                                    FredricT 😷💉🌻🌈
                                    wrote last edited by
                                    #39

                                    @pheonix I believe nothing has ever been safe 🤔 The only state that approaches it is "not compromized yet" 😅

                                    1 Reply Last reply
                                    0
                                    • Windy cityP Windy city

                                      They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                      This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                      Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                      We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                      https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                                      #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                      Bad Joanie 😷C This user is from outside of this forum
                                      Bad Joanie 😷C This user is from outside of this forum
                                      Bad Joanie 😷
                                      wrote last edited by
                                      #40

                                      @pheonix Oh ffs

                                      Right, it's back to pen and paper, so. JMJ.

                                      1 Reply Last reply
                                      0
                                      • Windy cityP Windy city

                                        They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                        This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                        Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                        We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                        https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                                        #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                        Chris HessertC This user is from outside of this forum
                                        Chris HessertC This user is from outside of this forum
                                        Chris Hessert
                                        wrote last edited by
                                        #41

                                        @pheonix

                                        This is hilarious. Next time hire some experienced, qualified, human coders? 🤣

                                        1 Reply Last reply
                                        0
                                        • Windy cityP Windy city

                                          They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                          This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                          Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                          We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                          https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                                          #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                          ploumP This user is from outside of this forum
                                          ploumP This user is from outside of this forum
                                          ploum
                                          wrote last edited by
                                          #42

                                          @pheonix :

                                          insert meme.

                                          "wait, is Microsoft a huge security hole?"

                                          "always have been"

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups