Tech News
← Home  ·  All topics

Terraform

2 GoKawiil briefs on this topic

Attackers exploit Vite server flaw to harvest AWS and Azure credentials

F5's honeypots detected a month-long scanning campaign exploiting CVE-2026-39364, a high-severity flaw in Vite versions 7.1.0-7.3.2 and pre-8.0.5, that lets unauthenticated attackers bypass access controls via crafted query parameters like ?raw or ?import&raw. Over 800 attacks and roughly 32,000 events were recorded, with attackers hunting for environment files, AWS and Azure credentials, Terraform state files, and system files like /etc/passwd. Most activity came from the US, Belgium, and the Netherlands, with some attackers routing through Google Cloud IPs and also exploiting older Vite access-control bugs.

Coder's Cloudflare-hosted registry hijacked to serve credential-stealing Terraform modules

Attackers breached Coder's Cloudflare infrastructure and inserted rogue servers into registry.coder.com's IP pool, causing some requests to be routed to malicious infrastructure instead of Coder's own. For roughly 14 hours on August 31, these servers distributed tampered Terraform modules containing code designed to harvest secrets from developer machines.