

So, Copilot for VSCode apparently got hit with an 8.8 CVE in November for, well, doing Copilot stuff. (RCE if you clone a strange repo and promptfondle it.)
Fixes were allegedly released on Nov 12th, but I can’t find anything in the Changelog on what those changes were, and how they would prevent Copilot from doing, well, Copilot stuff. (Although I may not be ITSec-savvy enough to know where such information would be found.)







I’m gonna leave here my idea, that an essential aspect of why GenAI is bad is that it is designed to extrude media that fits common human communication channels. This makes it perfect to choke out human-to-human communication over those channels, preventing knowledge exchange and social connection.