766 hosts breached via CVE-2025-55182 in Next.js apps, enabling mass credential theft and targeted follow-on attacks.
Part of the PlainSec briefing for 2026-04-05