
A mass-scanning operation is exploiting exposed Vite development servers to retrieve cloud credentials, configuration data, and other secrets from AWS and Azure environments. - Attackers exploit CVE-2026-39364 by manipulating query parameters to bypass file-access restrictions and return protected files in plaintext. - Scanning targets environment files, AWS and Azure credentials, Terraform state, serverless configurations, process environment data, and system files, with traversal and encoding variants used to evade filtering. - F5 observed more than 800 attacks and approximately 32,000 events over one month; activity originated mainly from the United States, Belgium, and the Netherlands and used Google Cloud IP ranges. - Related activity also exploited CVE-2025-30208, CVE-2025-31125, and CVE-2024-45811. Exposed servers should be patched and reachable secrets rotated.

