So let me get this straight:

in a 48-hour period, Microsoft-owned Github got compromised due to a malicious extension in Microsoft-owned VScode

and Microsoft-owned Windows has a system-integral RCE vulnerability thanks to Microsoft-owned Windows Defender... scanning a file.

you know, i'm starting to wonder if Microsoft's announced pivot to "security first" wasn't genuine

@neurovagrant

https://www.microsoft.com/en-us/security/blog/2025/10/13/building-a-lasting-security-culture-at-microsoft/

october last year. if you see the headshot of the person who wrote that, I think the term being used for that is 'mar a lago face'

@neurovagrant to be fair, those pivots are really just meant to inform program mangers which TFS dashboards they should be building for the next quarter.
@neurovagrant @jt_rebelo Hard to have anything first when github doesn't even have a CEO.

@t_var_s @jt_rebelo probably going to make Copilot the CEO in an "industry first, world first, revolutionary step"

as soon as they can convince Copilot to stop eating digital crayons

@neurovagrant Well, tbf they stopped loading all the passwords to memory on Edge startup

@neurovagrant

Pretty sure Microsoft operates under a "Security First" mindset where first is "first under the bus" when priorities are set

@neurovagrant gosh I completely forgot that they said that
@neurovagrant And the damnedest thing is … it's probably worse than we know.
@neurovagrant it’s not a gape, shit, I mean gap, if you fill your own hole with your own product?
@neurovagrant I found AV exploitation always the more promising approach for attackers rather than circumvention. The code in AVs is... wow.

@neurovagrant

The only thing surprising to me about that is that there hasn’t been a report of an organisation being compromised as a result of a vulnerability in InTune. If you get that, you have all three of the products I flagged as not coming close to following security best practices when I was there.

@neurovagrant

Vertically Integrated Security Marketectures are the all the rage, I heard.