# Campaign targets exposed Vite servers for cloud credentials

_Monday, September 14, 2026 at 12:15 PM EDT · Security · Latest · Tier 1 — Major_

![Campaign targets exposed Vite servers for cloud credentials — Primary](https://www.bleepstatic.com/content/hl-images/2026/05/05/hacker.jpg)

A mass-scanning campaign is targeting internet-exposed Vite development servers to retrieve AWS and Azure credentials and configuration files, BleepingComputer reported. The campaign exploits CVE-2026-39364, which the report says can bypass Vite file-read controls in specified 7.x and 8.x versions. F5 observed more than 800 attacks and about 32,000 raw events over a month. The report recommends updating Vite, restricting exposure, and rotating secrets reachable from publicly exposed unpatched servers.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/)

---
Canonical: https://techandbusiness.org/newswire/yMRhox8PpIU30pYjTtoJkJ
Retrieved: 2026-09-14T21:13:58.718Z
Publisher: Tech & Business (techandbusiness.org)
