Cloud Security Mass scanning campaign targets Vite development servers for cloud credentials September 15, 2026 Share By SC Staff (Adobe Stock) Coverage from Bleeping Computer indicates a widespread scanning campaign is actively exploiting a vulnerability in Vite development servers to steal cloud credentials and configurations from AWS and Azure deployments. The operation utilizes an exploit for CVE-2026-39364, a critical flaw affecting Vite versions 7.1.0 through 7.3.2 and the 8.x branch before 8.0.5, according to F5. This vulnerability allows unauthenticated attackers to bypass file access controls by manipulating HTTP GET requests, enabling them to retrieve sensitive files. F5 detected over 800 attacks and approximately 32,000 events in a month, with attackers focusing on environment files, cloud credentials, Terraform configurations, and serverless settings. The campaign also leveraged other Vite vulnerabilities, including CVE-2025-30208, CVE-2025-31125, and CVE-2024-45811. Most malicious activity originated from the United States, Belgium, and the Netherlands, using Google Cloud IP ranges for evasion. Developers are advised to update Vite to the latest version, block port 5173, and avoid exposing Vite publicly. If servers were exposed, rotating all secrets is recommended. Source: Bleeping Computer An In-Depth Guide to Cloud Security Get essential knowledge and practical strategies to fortify your cloud security. Learn More SC Staff Related AI/ML What CISOs need to know about Confidential Computing in 2026 Anand Kashyap September 8, 2026 Confidential Computing protects data in use, helping CISOs secure sensitive AI and cloud workloads. Cloud Security Upwind Security raises $300 million in Series C funding SC Staff September 4, 2026 Upwind Security offers a platform that automatically maps cloud assets and refreshes data every 30 seconds to account for frequent configuration changes. API security What Cloud Control Architecture Means for Executive Risk SC Media Editorial Intelligence, reviewed by Rajan Nagarajan August 31, 2026 Related Events Cybercast From prompt to exploit: How LLMs are changing API attacks On-Demand Event Cybercast Cloud Security: The AI Effect and How to Proceed On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Cloud Computing Greynet You can skip this ad in 5 seconds