Find notable cyber news and cases, enriched with sources, timelines, and signals.

Mass-scanning campaign targeting internet-exposed Vite development servers campaign expands hybrid attack activity

Campaign
First reported
Last updated
Happening score
H score 35
1 unique sources, 1 articles

Summary

Hide ▲

A mass-scanning campaign is targeting internet-exposed Vite development servers to steal AWS and Azure credentials and configurations, creating immediate risk of cloud compromise. The activity exploits CVE-2026-39364 in Vite 7.1.0–7.3.2 and 8.x before 8.0.5 by abusing query parameters to bypass file-read protections. F5 observed more than 800 attacks and about 32,000 raw events over a month, with traffic from the United States, Belgium, and the Netherlands. Defenders should patch Vite, restrict exposure on port 5173, block suspicious /@fs/ requests, and rotate secrets if vulnerable servers were public.

Related Happenings

F5 BIG-IP APM active exploitation wave (CVE-2025-53521)

Exploitation Wave
H score79 First: 02.04.2026 11:25 Last: 02.04.2026 11:25 Sources 1

About this happening: CVE-2025-53521 is being exploited against F5 BIG-IP APM systems, and F5 says new information in March 2026 changed the flaw from denial of service to remote...

F5 BIG-IP APM unauthenticated RCE (CVE-2025-53521)

Vulnerability
H score84 First: 30.03.2026 10:07 Last: 30.03.2026 10:07 Sources 1

About this happening: CVE-2025-53521 is an unauthenticated remote code execution flaw in F5 BIG-IP APM deployments with an access policy on a virtual server, including Appliance mode. F...

CISA KEV patch directive for CVE-2025-53521

Advisory/Mitigation
H score86 First: 30.03.2026 10:07 Last: 30.03.2026 10:07 Sources 1

About this happening: CISA added CVE-2025-53521 to its KEV catalog and told federal agencies to patch the F5 BIG-IP flaw within three days. The directive is urgent because the bug is be...

Stealth-first attacker tradecraft shifts toward covert exfiltration for extortion in 2025

Trend
H score28 First: 10.02.2026 16:00 Last: 10.02.2026 16:00 Sources 1

About this happening: Attackers are increasingly using stealthy persistence and evasion to silently exfiltrate data for extortion, making detection harder across monitored environments. A *...

Fortinet FortiClientEMS security update for CVE-2026-21643

Security Patch Release
H score54 First: 10.02.2026 06:38 Last: 10.02.2026 06:38 Sources 1

About this happening: Fortinet released security updates for FortiClientEMS to fix CVE-2026-21643, a critical SQL injection flaw that could let an unauthenticated attacker execute a...

Timeline

  1. 14.09.2026 19:15 2 articles · 2h ago

    F5 details mass-scanning campaign against exposed Vite servers

    Technical Analysis Update

    F5 detected a mass-scanning campaign against internet-exposed Vite development servers that is attempting to steal AWS and Azure credentials and configurations. The activity leverages CVE-2026-39364 in Vite 7.1.0 through 7.3.2 and 8.x before 8.0.5, using query-parameter abuse such as ?raw, ?import&raw, and ?import&url&inline to bypass deny-list filtering and retrieve files in plaintext. F5 also observed more than 800 attacks and approximately 32,000 raw events over a month, along with traversal and encoding variants, and the most active IPs also leveraged CVE-2025-30208, CVE-2025-31125, and CVE-2024-45811.

    Show sources