Hackers Target Exposed Vite Servers to Steal AWS and Azure Secrets
A mass-scanning campaign targets internet-exposed Vite development servers to steal cloud credentials linked to AWS and Azure environments.
Tag
17 results in the archive.
A mass-scanning campaign targets internet-exposed Vite development servers to steal cloud credentials linked to AWS and Azure environments.
Microsoft disclosed campaigns where attackers exploited third-party email systems for large-scale financial scam phishing and used passkey-themed social engineering techniques to compromise cloud accounts.
IDScan confirmed that hackers accessed customer data on its cloud platform, exposing over 153 million driver’s license scans with sensitive personal identity information.
Attackers exploit passkey-themed social engineering to bypass MFA and leverage Microsoft Graph for access to SharePoint, OneDrive, and email data, impacting cloud and identity security.
A 2026 Cloud Security Index revealed unique risk profiles in AWS, Azure, and Google Cloud through misconfiguration data from 3,000 organizations, challenging traditional multi-cloud security strategies.
JetBrains suffered a breach after attackers exploited an unpatched TeamCity vulnerability to access Cadence and extract AWS credentials.
Attackers breached Coder's Cloudflare infrastructure to push malicious Terraform modules that embed credential-stealing code, threatening developer credentials.
An unauthenticated remote code execution vulnerability in Langflow is exploited to steal sensitive OpenAI and AWS credentials, posing substantial risks to cloud and AI security.
CISA's red team assessments identified significant detection and response weaknesses in IT, cloud, and OT environments, revealing misconfigured Active Directory and excessive cloud permissions.
Over 9,300 AWS access keys leaked between 2022 and 2026 remain active, exposing corporate accounts to unauthorized access risks.
A threat actor is selling employee databases stolen from Microsoft Azure infrastructure of multiple Fortune 500 companies using compromised credentials, exposing sensitive account records and presenting an enterprise security risk.
Two malicious LiteLLM packages on PyPI in March contained credential-stealing code that potentially exposed over 2,100 organizations by capturing cloud and system secrets.
A Canadian individual admitted guilt in a data theft scheme targeting Snowflake cloud accounts, compromising sensitive data from at least 165 organizations and pursuing extortion.
Amgen reported a cloud data breach involving unauthorized access to patient health data and proprietary corporate information via third-party cloud systems.
A critical vulnerability in Azure Cosmos DB enabled attackers to escape the Gremlin query sandbox and gain full read/write access to multiple customer databases.
A crafted SVG submitted to Bing image search can execute commands as NT AUTHORITY\SYSTEM on Microsoft’s production servers, impacting multiple hosts with critical security implications.
The NadMesh Go botnet targets exposed AI services to harvest over 3,800 unique AWS keys, threatening cloud and Kubernetes environments.