CloudCompliance

Exposed Vite dev servers are being scanned for cloud keys

September 22, 2026. From issue 7 of The Compliance Brief, one story for Canadian companies running on AWS, Azure or Google Cloud.

Last reviewed 2026-09-22Written by Jacob Masse, TrazTech Inc.

Issue 7 of The Compliance Brief went to subscribers on September 22, 2026. One of its 5 stories bears on cloud security, misconfiguration and data residency, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: The Hacker News

F5 Labs described an automated mass-scanning campaign hunting internet-exposed Vite development servers. The goal is to pull AWS and Azure credentials, configuration files and infrastructure state files from those hosts.

Our take, in short

Development and preview environments get written out of audit scope constantly, and infrastructure state files are exactly where long-lived keys and connection strings sit. Ask your team whether any Vite dev server has ever been reachable from the internet, and if the answer is anything other than a confident no, rotate what was on that box.

Read the full take on traztech.ca

Also in issue 7

Outside cloud security, misconfiguration and data residency, but in the same email:

Older: issue 3 All issues on CloudCompliance Newer: issue 8