Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Vitec Software Group

Vitec Software Group Vendor Cyber Rating & Cyber Score

vitecsoftware.com

Software for unique needs: Vitec is a leading software company within vertical software and has its origin and headquarters in Umeå. We develop and deliver standardized software for various niches, such as pharmacies, banks, car workshops, real estate, healthcare and education.


VSG A.I CyberSecurity Scoring

VSG
Company Information
Website:http://www.vitecsoftware.com
Employees number:619
Number of followers:8,537
NAICS:5112
Industry Type:Software Development
Homepage:vitecsoftware.com
VSG Risk Score (AI oriented)
Between 750 and 799
logo
VSGSoftware Development
Updated:
14/09/2026
753/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
VSG Global Score (TPRM)
xxxx
logo
VSGSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

VSGFair
Current Score
753Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
753Before Incident
AUGUST 2026
755Before Incident
Vulnerability
01 Aug 2026VSG
Vite: Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials

Large-Scale Cyberattack Targets Exposed Vite Servers to Steal Cloud Credentials

753After Incident
CRITICAL-2
VIT1789410399
Large-Scale Cyberattack Targets Exposed Vite Servers to Steal Cloud Credentials In August 2026, security researchers at F5 detected a surge in automated attacks targeting internet-exposed Vite development servers, aiming to harvest AWS credentials, Azure access tokens, environment variables, and Infrastructure-as-Code (IaC) secrets. The campaign exploited CVE-2026-39364, a high-severity file-disclosure vulnerability in Vite versions 7.1.0–7.3.1 and 8.0.0–8.0.4, allowing unauthenticated attackers to bypass security controls and retrieve sensitive files. F5’s honeypot sensors recorded 807 session-grouped attacks and 32,000 raw events in August alone a dramatic increase from just 1,732 Vite-related file-read events over the prior three months. Attackers leveraged the vulnerability by sending crafted requests to Vite’s internal `@fs` route, combining query-string bypasses (e.g., `?raw`, `?import&raw`), path traversal, and double-encoded separators to access restricted files. Targets included `.env` files, AWS credential directories, Azure `accessTokens.json`, Terraform state files, and `/proc/self/environ`, which exposes an application’s environment without requiring its absolute path. The campaign’s infrastructure also tested older Vite access-control bypasses and probed for vulnerabilities in other frameworks, including CVE-2025-29927 (Next.js middleware bypass) and CVE-2025-31125 (a Known Exploited Vulnerability per CISA). Attackers used forged User-Agent strings (e.g., Googlebot, ClaudeBot) and spoofed X-Forwarded-For headers to evade detection, while most activity originated from Google Cloud Platform IPs (34.x, 35.x ranges). The U.S. saw the highest volume of attacks (17,297 events), followed by Belgium, the Netherlands, Singapore, Taiwan, and Japan. Exposed Vite servers often misconfigured via `--host` flags, container port mappings, or cloud security-group errors remain prime targets. Successful exploitation could grant attackers API keys, database passwords, cloud access credentials, and IaC secrets, enabling broader cloud compromise. Organizations are advised to upgrade to Vite 7.3.2 or 8.0.5+, remove development servers from public networks, and audit logs for suspicious requests targeting sensitive files. Compromised credentials, including AWS keys and Azure tokens, should be revoked and rotated immediately.
INCIDENT DETAILS -
TYPE
Cyberattack
MOTIVATION
Harvesting cloud credentials (AWS, Azure), environment variables, and IaC secrets
IMPACT
Data Compromised: AWS credentials, Azure access tokens, environment variables, IaC secrets, database passwords, API keysSystems Affected: Internet-exposed Vite development serversOperational Impact: Potential broader cloud compromise due to stolen credentials
DATA BREACH
AWS credentialsAzure access tokensEnvironment variablesIaC secretsDatabase passwordsAPI keysSensitivity Of Data: HighData Exfiltration: Yes.env filesAWS credential directoriesAzure accessTokens.jsonTerraform state files/proc/self/environ
JULY 2026
755Before Incident
JUNE 2026
755Before Incident
MAY 2026
756Before Incident
APRIL 2026
756Before Incident
MARCH 2026
756Before Incident
FEBRUARY 2026
756Before Incident
JANUARY 2026
756Before Incident
DECEMBER 2025
756Before Incident
NOVEMBER 2025
756Before Incident
OCTOBER 2025
756Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for VSG ?
?
What was VSG's A.I Rankiteo Cyber Score in August 2026 ?
?
What was VSG's A.I Rankiteo Cyber Score in July 2026 ?
?
What was VSG's A.I Rankiteo Cyber Score in June 2026 ?
?
What was VSG's A.I Rankiteo Cyber Score in May 2026 ?
?
What was VSG's A.I Rankiteo Cyber Score in April 2026 ?
?
What was VSG's A.I Rankiteo Cyber Score in March 2026 ?
?
What was VSG's A.I Rankiteo Cyber Score in February 2026 ?
?
What was VSG's A.I Rankiteo Cyber Score in January 2026 ?
?
What was VSG's A.I Rankiteo Cyber Score in December 2025 ?
?
What was VSG's A.I Rankiteo Cyber Score in November 2025 ?
?
What was VSG's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on VSG's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with VSG ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view VSG's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?