Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Former top civil servant received pay-off of nearly £860,000

    September 14, 2026

    New York Seizes a Dozen Celebrity Deepfake Websites

    September 14, 2026

    Hackers target exposed Vite dev servers to steal AWS, Azure secrets

    September 14, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Former top civil servant received pay-off of nearly £860,000
    • New York Seizes a Dozen Celebrity Deepfake Websites
    • Hackers target exposed Vite dev servers to steal AWS, Azure secrets
    • Here’s what’s actually different in the final CLARITY Act
    • Summer Training: Catching Up With NASA’s Astronaut Candidates
    • Can we stop ships from killing the Mediterranean’s last great whales?
    • Hybrid electric propulsion at the heart of next-gen LNG carrier design
    • Canada should become an EU state in all but name. Here’s how to make that a reality | Fabian Zuleeg
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, September 14
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers target exposed Vite dev servers to steal AWS, Azure secrets

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 14, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments.

    The operation leverages an exploit for CVE-2026-39364, a high-severity vulnerability that allows bypassing file read/access controls in Vite versions 7.1.0 through 7.3.2, as well as the 8.x branch before 8.0.5.

    The flaw was disclosed on April 7 and allows an unauthenticated attacker to manipulate query parameters in an HTTP GET request to bypass security restrictions and retrieve files in plaintext from locations that should normally be out of their reach.

    Technology company F5 detected the attacks through its honeypot sensors, observing more than 800 attacks and approximately 32,000 raw events over a month.

    “When specific parameters such as ?raw, ?import&raw, or ?import&url&inline are appended to a request, the server fails to enforce deny-list filtering and serves the target file with an HTTP 200 response,” F5 explains.

    After breaching a system, the scanning focused on valuable secrets by using extensive wordlists for the following types of data:

    • .env, .env.production, .env.local, and other environment files
    • AWS credential files from several possible home directories
    • AWS configuration files and credential backups
    • Azure credentials and access tokens
    • Terraform state and variable files
    • Serverless configuration/state
    • /proc/self/environ, /proc/1/environ, and /proc/self/cwd/.env
    • /etc/passwd

    F5 notes that the operation also tried traversal and encoding variants, including double-encoded traversal sequences, apparently to get past reverse proxies or WAF normalization.

    Most of the observed malicious activity originated from the United States, Belgium, and the Netherlands, with the attackers using Google Cloud IP ranges for evasion.

    The most active IP addresses also leveraged other access control flaws in Vite: CVE-2025-30208, CVE-2025-31125 (flagged as actively exploited), and CVE-2024-45811.

    How to protect Vite

    Although Vite normally binds to localhost, F5 researchers say that developers often expose it online through passing the –host flag, setting the server.host, or misconfigured Docker port mappings.

    The technology company recommends updating Vite servers to the latest version, which addresses the exploited flaws. Developers should also block access through port 5173, block suspicious /@fs/ requests, and avoid trusting crawler User-Agent strings.

    The top sources for the malicious attempts are 34.14.15[.]105, 34.16.200[.]129, and 34.11.196[.]206, which should be blocklisted.

    If unpatched Vite servers were publicly exposed, it is recommended to rotate all secrets in the reach of the vulnerable system.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    AWS Azure dev exposed hackers Secrets Servers Steal Target Vite
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

    Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development

    Webinar: How malicious OAuth apps can lead to Google Workspace breaches

    Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

    CISOs Race to Control AI Agents Without Destroying Their Value

    What the 3M ChatGPT case reveals about AI governance

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Former top civil servant received pay-off of nearly £860,000

    September 14, 2026

    New York Seizes a Dozen Celebrity Deepfake Websites

    September 14, 2026

    Hackers target exposed Vite dev servers to steal AWS, Azure secrets

    September 14, 2026

    Here’s what’s actually different in the final CLARITY Act

    September 14, 2026
    Latest Posts

    What Is an Air-Gapped Bitcoin Wallet? Why the Coldcard Exploit Changes the Conversation About Offline Security

    August 3, 2026

    18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

    August 3, 2026

    T-Mobile will give you the new Samsung Galaxy Z Flip for practically nothing if you preorder now

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Former top civil servant received pay-off of nearly £860,000

    September 14, 2026

    New York Seizes a Dozen Celebrity Deepfake Websites

    September 14, 2026

    Hackers target exposed Vite dev servers to steal AWS, Azure secrets

    September 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.