bleeping-computer · Crawled Sep 14, 2026

Hackers target exposed Vite dev servers to steal AWS, Azure secrets

3 IoCs 4 CVEs
Read original article ↗

AI Summary

Hackers are conducting a mass-scanning campaign targeting internet-exposed Vite development servers, exploiting CVE-2026-39364 to bypass file access controls and steal sensitive cloud credentials from AWS and Azure environments. The attackers use specific query parameters to retrieve environment files, cloud credentials, Terraform configurations, and system information. The activity has been observed originating from IP addresses in the United States, Belgium, and the Netherlands, with attackers leveraging Google Cloud infrastructure for evasion.

AI-extracted · verify before operational use

Extracted Entities 4 found

Indicators of Compromise 3 extracted

Type Value Detail
IP 34[.]14[.]15[.]105 Details →
IP 34[.]16[.]200[.]129 Details →
IP 34[.]11[.]196[.]206 Details →