CISA: Hackers now exploit max severity GitLab flaw in attacks
GitLab CVE-2023-7028 (CVSS 10.0) enables unauthenticated account takeover. Patched Jan 2024 but unpatched widely; CISA confirms active exploitation exposing code, CI/CD creds, and secrets.