Vite 배포의 보안 취약점을 이용한 대규모 스캔 캠페인이 보고됐다.
사이버 보안 연구원들은 Vite 배포를 목표로 하는 대규모 스캔 캠페인에 대한 세부 정보를 공개했다. 이 자동화된 공격은 인터넷에 노출된 Vite 개발 서버를 겨냥해 AWS와 Microsoft Azure의 클라우드 자격 증명 및 구성을 훔치는 것을 목표로 하고 있다. 이러한 취약점을 통해 인프라 상태 파일이 유출될 위험이 증가하고 있다.
A mass-scanning campaign has been reported targeting Vite deployments.
Cybersecurity researchers have disclosed details about a mass-scanning campaign aimed at Vite deployments. This automated effort targets internet-exposed Vite development servers to steal cloud credentials and configurations from AWS and Microsoft Azure instances. The risk of exposing infrastructure state files has also increased due to this vulnerability.