hacker-news · Crawled Sep 15, 2026

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

2 IoCs 1 CVEs
Read original article ↗

AI Summary

A mass-scanning campaign has been exploiting CVE-2026-39364, a high-severity vulnerability in Vite, to extract sensitive data from internet-exposed development servers. The flaw allows unauthenticated attackers to bypass file access restrictions by manipulating query parameters, enabling them to retrieve cloud credentials, environment configurations, and infrastructure state files from AWS and Azure environments. Attackers use spoofed User-Agent headers and forged X-Forwarded-For headers to evade detection, with significant malicious traffic originating from Google Cloud Platform IP ranges in the U.S., Belgium, the Netherlands, Singapore, and Taiwan.

AI-extracted · verify before operational use

Extracted Entities 1 found

Indicators of Compromise 2 extracted

Type Value Detail
IP 34[.]94[.]237[.]62 Details →
IP 104[.]28[.]219[.]193 Details →

MITRE ATT&CK TTPs 1 techniques