INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials
| 2026-09-15 11:12 MEDIUM HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The recent incident data reveals a sophisticated cyber attack targeting Vite deployments, with malicious activity originating from the US, Belgium, Netherlands, Singapore, and Taiwan. The attackers exploited an unpatched security flaw in Google Cloud Platform ranges (34.x and 35.x) to extract sensitive data from exposed dev servers. This mass-scanning campaign leveraged CVE-2026-39364, a high-severity vulnerability that allows unauthorized access via query parameter manipulation. Researchers have disclosed details of this attack, which can compromise plaintext API secrets, database passwords, and cloud administrative credentials. The attackers require three conditions to be met for an app to be deemed affected: explicit exposure, sensitive file existence in allowed directories, and denial of a specific pattern matching a denied file. This highlights the importance of timely patching and robust security measures to prevent such attacks from succeeding.
Technical Mitigations AI-generated
* Implement a secure query parameter manipulation policy to prevent attackers from exploiting the CVE-2026-39364 vulnerability by appending bypass query parameters.
* Configure Vite development servers to use a secure configuration file path, such as `<a href="/auth/login?next=/detail/aveZo6ABGvYhsJJTP2k3" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a> = false` and `<a href="/auth/login?next=/detail/aveZo6ABGvYhsJJTP2k3" class="ioc-censored-pill text-decoration-none" title="Protected IoC: Sign in to view" data-bs-toggle="tooltip"><span class="badge bg-black text-warning border border-warning border-opacity-75 font-monospace ioc-lock-tag align-middle"><i class="bi bi-lock-fill me-1"></i>[IOC HIDDEN • LOGIN REQUIRED]</span></a> = [/* allowed directories */]`, to restrict access to sensitive files.
* Monitor server logs for suspicious activity related to AWS or Azure credentials being accessed through the `/@fs/ endpoint`.
* Regularly update Vite versions to the latest available security patches, including CVE-2026-39364, and ensure that all dependencies are up-to-date to prevent exploitation of known vulnerabilities.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
se•••••.host
en•••••.local
en•••••.production
te•••••.tfstate
34.11.•••.•••
34.14.•••.•••
34.16.•••.•••
34.94.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2024-45811CVE-2024-45811
CVE-2025-30208CVE-2025-30208
CVE-2025-31125CVE-2025-31125
CVE-2026-39364CVE-2026-39364
Target & Sectors
Global Scope
technologytechnology
Incident Timeline
April 7
The mass-scanning campaign exploited a vulnerability in Vite to extract cloud credentials from exposed Dev servers.
April 2026
The attackers used Google Cloud Platform ranges (34.x and 35.x) to exploit a vulnerability in Vite's configuration directory scanning, allowing them to extract sensitive cloud credentials from exposed dev servers.
Click on any entity below to view its context and source!
observable
server.fs.deny
"On the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended," Vite said in an
advisory
for the flaw in April 2026.
general_metric
200 responses
"On the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended," Vite said in an
advisory
for the flaw in April 2026.
organisation
Docker
"When developers expose the service by passing the --host flag, setting server.host, or misconfiguring Docker container port mappings, the development server becomes directly reachable over the local network or public internet.
organisation
API
This can have severe implications when the request is used to target configuration directories, granting the attackers unauthorized access to plaintext API secrets, database passwords, and cloud administrative credentials.
organisation
34.94.237[.]62
The requests also inject forged X-Forwarded-For and X-Real-IP values (e.g., 34.94.237[.]62 and 104.28.219[.]193) to get around IP-based access lists and complicate log analysis.
organisation
IP
The requests also inject forged X-Forwarded-For and X-Real-IP values (e.g., 34.94.237[.]62 and 104.28.219[.]193) to get around IP-based access lists and complicate log analysis.
August 2026
Threat actors used a CVE-2026-39364 exploit to target Vite servers, allowing them to extract cloud credentials by manipulating query parameters.
Click on any entity below to view its context and source!
organisation
CVE-2026-39364
The credential harvesting activity, observed in August 2026, has been found to leverage an exploit for CVE-2026-39364 (CVSS score: 8.2), a high-severity security flaw in Vite that could permit an unauthenticated attacker to bypass security restrictions via query parameter manipulation and leak sensitive data, including files specified by server.fs.deny.
observable
server.fs.deny
The credential harvesting activity, observed in August 2026, has been found to leverage an exploit for CVE-2026-39364 (CVSS score: 8.2), a high-severity security flaw in Vite that could permit an unauthenticated attacker to bypass security restrictions via query parameter manipulation and leak sensitive data, including files specified by server.fs.deny.
data_breach
8.2 credential harvesting activity
The credential harvesting activity, observed in August 2026, has been found to leverage an exploit for CVE-2026-39364 (CVSS score: 8.2), a high-severity security flaw in Vite that could permit an unauthenticated attacker to bypass security restrictions via query parameter manipulation and leak sensitive data, including files specified by server.fs.deny.
Sep 15, 2026
Threat actors used a mass-scanning campaign to exploit a vulnerability in Vite development servers, compromising exposed instances on Amazon Web Services and Microsoft Azure.
Click on any entity below to view its context and source!
organisation
Microsoft Azure
The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per
F5 Labs
.
2026/09/15
Researchers disclosed details of a mass-scanning campaign that exploited vulnerabilities in Vite to steal cloud credentials and configurations from AWS and Azure deployments.
Click on any entity below to view its context and source!
organisation
Google
Most of the observed malicious activity originated from the United States, Belgium, and the Netherlands, with the attackers using Google Cloud IP ranges for evasion.
organisation
CVE-2026-39364
The operation leverages an exploit for CVE-2026-39364, a high-severity vulnerability that allows bypassing file read/access controls in Vite versions 7.1.0 through 7.3.2, as well as the 8.x branch before 8.0.5.
infrastructure
7.1.0
The operation leverages an exploit for CVE-2026-39364, a high-severity vulnerability that allows bypassing file read/access controls in Vite versions 7.1.0 through 7.3.2, as well as the 8.x branch before 8.0.5.
infrastructure
7.3.2
The operation leverages an exploit for CVE-2026-39364, a high-severity vulnerability that allows bypassing file read/access controls in Vite versions 7.1.0 through 7.3.2, as well as the 8.x branch before 8.0.5.
infrastructure
8.0.5
The operation leverages an exploit for CVE-2026-39364, a high-severity vulnerability that allows bypassing file read/access controls in Vite versions 7.1.0 through 7.3.2, as well as the 8.x branch before 8.0.5.
organisation
Vulnerability / Cloud Security
Ravie Lakshmanan
Sep 15, 2026
Vulnerability / Cloud Security
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data.
organisation
IP
The most active IP addresses also leveraged other access control flaws in Vite: CVE-2025-30208, CVE-2025-31125 (
flagged as actively exploited
), and CVE-2024-45811.
organisation
CVE-2025-31125
The most active IP addresses also leveraged other access control flaws in Vite: CVE-2025-30208, CVE-2025-31125 (
flagged as actively exploited
), and CVE-2024-45811.
organisation
Terraform
After breaching a system, the scanning focused on valuable secrets by using extensive wordlists for the following types of data:
.env, .env.production, .env.local, and other environment files
AWS credential files from several possible home directories
AWS configuration files and credential backups
Azure credentials and access tokens
Terraform state and variable files
Serverless configuration/state
/proc/self/environ, /proc/1/environ, and /proc/self/cwd/.env
/etc/passwd
F5 notes
that the operation also tried traversal and encoding variants, including double-encoded traversal sequences, apparently to get past reverse proxies or WAF normalization.
organisation
AWS
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Tactical Metrics
Metrics
data_breach
8
Credential Harvesting Activity
Click for context!
The credential harvesting activity, observed in August 2026, has been found to leverage an exploit for CVE-2026-39364 (CVSS score: 8.2), a high-severity security flaw in Vite that could permit an unauthenticated attacker to bypass security restrictions via query parameter manipulation and leak sensitive data, including files specified by server.fs.deny.
Metrics
infrastructure
7.1.0
Software Version
The operation leverages an exploit for CVE-2026-39364, a high-severity vulnerability that allows bypassing file read/access controls in Vite versions 7.1.0 through 7.3.2, as well as the 8.x branch before 8.0.5.
Metrics
infrastructure
7.3.2
Software Version
The operation leverages an exploit for CVE-2026-39364, a high-severity vulnerability that allows bypassing file read/access controls in Vite versions 7.1.0 through 7.3.2, as well as the 8.x branch before 8.0.5.
Metrics
infrastructure
8.0.5
Software Version
The operation leverages an exploit for CVE-2026-39364, a high-severity vulnerability that allows bypassing file read/access controls in Vite versions 7.1.0 through 7.3.2, as well as the 8.x branch before 8.0.5.
Intelligence Sources
The Hacker News
2026-09-15
BleepingComputer
2026-09-14
Hackers target exposed Vite dev servers to steal AWS, Azure secrets
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-16T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
13x
organisation
Identified Entity
CVE-2026-39364
entity
6x
timeline
Temporal Reference
Sep 15, 2026
date
5x
source region
Origin Country
Belgium
country
4x
tactic
MITRE ATT&CK Technique
T1588.005 - Exploits
technique
4x
vulnerability
Exploited CVE
CVE-2026-39364
cve
3x
attribution
Attributing Entity
ClaudeBot
authority
3x
infrastructure
Software Version
7.1.0
version
Contextual Telemetry
Context Block
7 METRICS
tactic
Cyber Operation Type
Reconnaissance
tactic
data breach
Credential Harvesting Activity
8
credential harvesting activity
general metric
Responses
200
responses
general metric
Sep
15
sep
industry
Targeted Sector
Technology
sector
general metric
Attacks
800
attacks
general metric
Raw Events
32,000
raw events
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.