Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Darkly)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. Uncategorized
  3. They finally did it.

They finally did it.

Scheduled Pinned Locked Moved Uncategorized
noaimicroslopmicrosoftwindowsprogramming
46 Posts 40 Posters 26 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Windy cityP This user is from outside of this forum
    Windy cityP This user is from outside of this forum
    Windy city
    wrote last edited by
    #28

    @bluszcz wow

    1 Reply Last reply
    0
    • MureniusM Murenius

      @pheonix That's what you get for using AI in development. What could possibly go wrong?

      Windy cityP This user is from outside of this forum
      Windy cityP This user is from outside of this forum
      Windy city
      wrote last edited by
      #29

      @Murenius but..but AGI?

      1 Reply Last reply
      0
      • Windy cityP Windy city

        They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

        This CVE is an 8.8 severity RCE in Notepad of all things lmao.

        Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

        We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

        https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

        #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

        Hasan SarptaşS This user is from outside of this forum
        Hasan SarptaşS This user is from outside of this forum
        Hasan Sarptaş
        wrote last edited by
        #30

        @pheonix I never use Notepad for years. I prefer Notepad3 or recently I moved to Zed.

        https://bsky.app/profile/zed.dev

        1 Reply Last reply
        0
        • Windy cityP Windy city

          They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

          This CVE is an 8.8 severity RCE in Notepad of all things lmao.

          Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

          We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

          https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

          #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

          Mans RM This user is from outside of this forum
          Mans RM This user is from outside of this forum
          Mans R
          wrote last edited by
          #31

          @pheonix You have to click a link. Merely opening the file isn't enough if I'm reading it correctly. That makes it comparable to Internet Explorer back when it would happily download and run any .exe. So pretty stupid.

          1 Reply Last reply
          0
          • BSM (sw.s) 🇨🇭B BSM (sw.s) 🇨🇭

            @pheonix

            One of the reasons, why I use Notepad++ (https://notepad-plus-plus.org/downloads/)

            JamesJ This user is from outside of this forum
            JamesJ This user is from outside of this forum
            James
            wrote last edited by
            #32

            @bsm @pheonix

            Notepad++ is my go-to choice for most everything. Simple, multi-tab app with good cleanup, find-n-replace, and macro tools.

            1 Reply Last reply
            0
            • Windy cityP Windy city

              They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

              This CVE is an 8.8 severity RCE in Notepad of all things lmao.

              Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

              We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

              https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

              #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

              ? Offline
              ? Offline
              Guest
              wrote last edited by
              #33

              @pheonix No, no it is not. All corporate compute needs to be in the sea.

              1 Reply Last reply
              0
              • Windy cityP Windy city

                They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                Handler SkylerS This user is from outside of this forum
                Handler SkylerS This user is from outside of this forum
                Handler Skyler
                wrote last edited by
                #34

                @pheonix Given that WordPad had that built in, and MS killed it; not surprised

                1 Reply Last reply
                0
                • Windy cityP Windy city

                  They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                  This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                  Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                  We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                  https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                  #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                  Kg. Madee Ⅱ.K This user is from outside of this forum
                  Kg. Madee Ⅱ.K This user is from outside of this forum
                  Kg. Madee Ⅱ.
                  wrote last edited by
                  #35

                  @pheonix and I still think they should have left support for formatted t3xt where it belongs, in Wordpad
                  Notepad could use syntax highlighting & auto-completion maybe ...

                  1 Reply Last reply
                  0
                  • Windy cityP Windy city

                    They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                    This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                    Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                    We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                    #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                    D This user is from outside of this forum
                    D This user is from outside of this forum
                    DecebalTheThracian
                    wrote last edited by
                    #36

                    @pheonix Windows 11 = ☠️

                    1 Reply Last reply
                    0
                    • Windy cityP Windy city

                      They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                      This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                      Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                      We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                      https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                      #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                      Don Hawkins - W7DAHD This user is from outside of this forum
                      Don Hawkins - W7DAHD This user is from outside of this forum
                      Don Hawkins - W7DAH
                      wrote last edited by
                      #37

                      @pheonix @duniamelayu Linux?

                      1 Reply Last reply
                      0
                      • Windy cityP Windy city

                        They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                        This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                        Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                        We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                        https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                        #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                        GinkgoG This user is from outside of this forum
                        GinkgoG This user is from outside of this forum
                        Ginkgo
                        wrote last edited by
                        #38

                        @pheonix Don’t forget that Notepad++ was compromised recently too by state actors… https://notepad-plus-plus.org/news/hijacked-incident-info-update/

                        1 Reply Last reply
                        0
                        • Windy cityP Windy city

                          They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                          This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                          Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                          We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                          https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                          #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                          FredricT 😷💉🌻🌈F This user is from outside of this forum
                          FredricT 😷💉🌻🌈F This user is from outside of this forum
                          FredricT 😷💉🌻🌈
                          wrote last edited by
                          #39

                          @pheonix I believe nothing has ever been safe 🤔 The only state that approaches it is "not compromized yet" 😅

                          1 Reply Last reply
                          0
                          • Windy cityP Windy city

                            They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                            This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                            Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                            We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                            https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                            #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                            Bad Joanie 😷C This user is from outside of this forum
                            Bad Joanie 😷C This user is from outside of this forum
                            Bad Joanie 😷
                            wrote last edited by
                            #40

                            @pheonix Oh ffs

                            Right, it's back to pen and paper, so. JMJ.

                            1 Reply Last reply
                            0
                            • Windy cityP Windy city

                              They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                              This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                              Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                              We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                              https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                              #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                              Chris HessertC This user is from outside of this forum
                              Chris HessertC This user is from outside of this forum
                              Chris Hessert
                              wrote last edited by
                              #41

                              @pheonix

                              This is hilarious. Next time hire some experienced, qualified, human coders? 🤣

                              1 Reply Last reply
                              0
                              • Windy cityP Windy city

                                They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                                #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                ploumP This user is from outside of this forum
                                ploumP This user is from outside of this forum
                                ploum
                                wrote last edited by
                                #42

                                @pheonix :

                                insert meme.

                                "wait, is Microsoft a huge security hole?"

                                "always have been"

                                1 Reply Last reply
                                0
                                • Windy cityP Windy city

                                  They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                  This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                  Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                  We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                  https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                                  #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                  SibrosanS This user is from outside of this forum
                                  SibrosanS This user is from outside of this forum
                                  Sibrosan
                                  wrote last edited by
                                  #43

                                  @pheonix Valt het jullie ook op dat een klaarstaande Windows-update de werking van applicaties beïnvloedt? Als programma's op een vreemde manier reageren en het icoontje "afsluiten en updaten" is zichtbaar, weet ik al weer hoe laat het is. Na updaten en herstarten werkt het dan weer normaal.

                                  1 Reply Last reply
                                  0
                                  • Windy cityP Windy city

                                    They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                    This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                    Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                    We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                                    #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                    ColinC This user is from outside of this forum
                                    ColinC This user is from outside of this forum
                                    Colin
                                    wrote last edited by
                                    #44

                                    @pheonix another reason to switch on linux, only thing that can hold someone from switching is adobe software

                                    1 Reply Last reply
                                    0
                                    • Windy cityP Windy city

                                      They finally did it. Microsoft has successfully over-engineered a text editor into a threat vector.

                                      This CVE is an 8.8 severity RCE in Notepad of all things lmao.

                                      Apparently, the "innovation" of adding markdown support came with the ability of launching unverified protocols that load and execute remote files.

                                      We have reached a point where the simple act of opening a .md file in a native utility can compromise your system. Is nothing safe anymore? 😭

                                      https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20841

                                      #noai #microslop #microsoft #windows #programming #writing #windows11 #enshittification #cybersecurity #infosec #technology

                                      oatmealO This user is from outside of this forum
                                      oatmealO This user is from outside of this forum
                                      oatmeal
                                      wrote last edited by
                                      #45

                                      @pheonix @microsoft always delivers

                                      1 Reply Last reply
                                      0
                                      • ⠠⠵ avukoA ⠠⠵ avuko

                                        @jkb @pheonix That seems to be the case, although the weakness is in Microsoft Notepad incorrectly handling “an unverified protocol”, not in something the user then has to do or interact with. Besides clicking a link.

                                        This reads to me like an URI protocol handling issue.

                                        And that functionality is not something they’d have to reinvent or vibe code.

                                        You know, with their proprietary plain text editor running on their proprietary OS, and next to their proprietary file explorer, their proprietary internet browser, their proprietary email client and proprietary network agents.

                                        All their proprietary software handling URI protocols… RIGHT THERE.

                                        JKBJ This user is from outside of this forum
                                        JKBJ This user is from outside of this forum
                                        JKB
                                        wrote last edited by
                                        #46

                                        @avuko @pheonix Yes, indeed. And yes indeed this is something that should have never happened, the whole situation is shameful.

                                        I was just pointing out that this vulnerability requires additional user input (albeit a very likely user input that normally shouldn't raise any concern), it's not one of those nightmare situations in which the mere opening of a file triggers an exploit.

                                        1 Reply Last reply
                                        0
                                        Reply
                                        • Reply as topic
                                        Log in to reply
                                        • Oldest to Newest
                                        • Newest to Oldest
                                        • Most Votes


                                        • Login

                                        • Don't have an account? Register

                                        • Login or register to search.
                                        Powered by NodeBB Contributors
                                        • First post
                                          Last post
                                        0
                                        • Categories
                                        • Recent
                                        • Tags
                                        • Popular
                                        • World
                                        • Users
                                        • Groups