
Critical Cybersecurity and DevOps News Updates | 2026.04.04 | April 4th, 2026
➔ Google patched CVE-2026-5281, a use-after-free bug in Dawn (WebGPU), marking the fourth Chrome zero-day exploited in the wild this year. Affected versions were updated to 146.0.7680.177/178 for Windows, macOS, and Linux. ➔ CVE-2026-5281 is the fourth Chrome zero-day patched in 2026, following CVE-2026-2441 (CSSFontFeatureValuesMap iterator invalidation), CVE-2026-3909 (Skia out-of-bounds write), and CVE-2026-3910 (V8 inappropriate implementation). All four were confirmed exploited in attacks before patches shipped. ➔ Attackers exploiting CVE-2025-55182 breached 766 Next.js hosts and exfiltrated database credentials, SSH keys, AWS secrets, Stripe API keys, and GitHub tokens. The Nexus Listener framework was used to automate the credential harvesting operation across targets. ➔ A React2Shell exploitation campaign using automated scanning compromised over 750 systems in a coordinated credential harvesting operation. The Nexus Listener framework enabled large-scale, systematic access acr
Continue reading on Dev.to
Opens in a new tab

