Mass-scanning campaign targeting internet-exposed Vite development servers campaign expands hybrid attack activity
Campaign
Summary
Hide ▲
Show ▼
A mass-scanning campaign is targeting internet-exposed Vite development servers to steal AWS and Azure credentials and configurations, creating immediate risk of cloud compromise. The activity exploits CVE-2026-39364 in Vite 7.1.0–7.3.2 and 8.x before 8.0.5 by abusing query parameters to bypass file-read protections. F5 observed more than 800 attacks and about 32,000 raw events over a month, with traffic from the United States, Belgium, and the Netherlands. Defenders should patch Vite, restrict exposure on port 5173, block suspicious /@fs/ requests, and rotate secrets if vulnerable servers were public.
Related Happenings
F5 BIG-IP APM active exploitation wave (CVE-2025-53521)
Exploitation Wave
H score79
First: 02.04.2026 11:25
Last: 02.04.2026 11:25
Sources 1
About this happening:
CVE-2025-53521 is being exploited against F5 BIG-IP APM systems, and F5 says new information in March 2026 changed the flaw from denial of service to remote...
F5 BIG-IP APM active exploitation wave (CVE-2025-53521)
Exploitation WaveAbout this happening: CVE-2025-53521 is being exploited against F5 BIG-IP APM systems, and F5 says new information in March 2026 changed the flaw from denial of service to remote...
F5 BIG-IP APM unauthenticated RCE (CVE-2025-53521)
Vulnerability
H score84
First: 30.03.2026 10:07
Last: 30.03.2026 10:07
Sources 1
About this happening:
CVE-2025-53521 is an unauthenticated remote code execution flaw in F5 BIG-IP APM deployments with an access policy on a virtual server, including Appliance mode. F...
F5 BIG-IP APM unauthenticated RCE (CVE-2025-53521)
VulnerabilityAbout this happening: CVE-2025-53521 is an unauthenticated remote code execution flaw in F5 BIG-IP APM deployments with an access policy on a virtual server, including Appliance mode. F...
CISA KEV patch directive for CVE-2025-53521
Advisory/Mitigation
H score86
First: 30.03.2026 10:07
Last: 30.03.2026 10:07
Sources 1
About this happening:
CISA added CVE-2025-53521 to its KEV catalog and told federal agencies to patch the F5 BIG-IP flaw within three days. The directive is urgent because the bug is be...
CISA KEV patch directive for CVE-2025-53521
Advisory/MitigationAbout this happening: CISA added CVE-2025-53521 to its KEV catalog and told federal agencies to patch the F5 BIG-IP flaw within three days. The directive is urgent because the bug is be...
Stealth-first attacker tradecraft shifts toward covert exfiltration for extortion in 2025
Trend
H score28
First: 10.02.2026 16:00
Last: 10.02.2026 16:00
Sources 1
About this happening:
Attackers are increasingly using stealthy persistence and evasion to silently exfiltrate data for extortion, making detection harder across monitored environments. A *...
Stealth-first attacker tradecraft shifts toward covert exfiltration for extortion in 2025
TrendAbout this happening: Attackers are increasingly using stealthy persistence and evasion to silently exfiltrate data for extortion, making detection harder across monitored environments. A *...
Fortinet FortiClientEMS security update for CVE-2026-21643
Security Patch Release
H score54
First: 10.02.2026 06:38
Last: 10.02.2026 06:38
Sources 1
About this happening:
Fortinet released security updates for FortiClientEMS to fix CVE-2026-21643, a critical SQL injection flaw that could let an unauthenticated attacker execute a...
Fortinet FortiClientEMS security update for CVE-2026-21643
Security Patch ReleaseAbout this happening: Fortinet released security updates for FortiClientEMS to fix CVE-2026-21643, a critical SQL injection flaw that could let an unauthenticated attacker execute a...
Timeline
-
14.09.2026 19:15 2 articles · 2h ago
F5 details mass-scanning campaign against exposed Vite servers
Technical Analysis UpdateF5 detected a mass-scanning campaign against internet-exposed Vite development servers that is attempting to steal AWS and Azure credentials and configurations. The activity leverages CVE-2026-39364 in Vite 7.1.0 through 7.3.2 and 8.x before 8.0.5, using query-parameter abuse such as ?raw, ?import&raw, and ?import&url&inline to bypass deny-list filtering and retrieve files in plaintext. F5 also observed more than 800 attacks and approximately 32,000 raw events over a month, along with traversal and encoding variants, and the most active IPs also leveraged CVE-2025-30208, CVE-2025-31125, and CVE-2024-45811.
Show sources
- Hackers target exposed Vite dev servers to steal AWS, Azure secrets — www.bleepingcomputer.com — 14.09.2026 19:15
- Hackers target exposed Vite dev servers to steal AWS, Azure secrets — www.bleepingcomputer.com — 14.09.2026 19:15