UK NCSC CTO’s weekly cyber roundup, mostly threat intel, vuln research, PQC migration, and the latest AI panic with diagrams.
trending4
01 02 CVE record for a qs limit-bypass DoS via comma-separated a[]= values, fixed in v6.16.0, because arrays needed more room.03 PoC for a Nacos 3.x auth-scope bug, unauth account creation and server takeover on 3.0.0 through 3.2.3.04 Pre-auth RCE in TeamCity turns on an XStream allowlist miss, then chains agent polling, gadgets, and an HSQLDB file write.