VSG A.I CyberSecurity Scoring
VSG
Company Information
Website:http://www.vitecsoftware.com
Employees number:619
Number of followers:8,537
NAICS:5112
Industry Type:Software Development
Homepage:vitecsoftware.com
VSG Risk Score (AI oriented)
Between 750 and 799
VSGSoftware Development
Updated:
14/09/2026
14/09/2026
753/1000
Fair
Baa
VSG Global Score (TPRM)
xxxx
VSGSoftware Development
Score locked

VSGFair
Current Score
753Baa (FAIR)
01000
1 incidents
-2 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
753
AUGUST 2026
755
Vulnerability
01 Aug 2026 • VSG
Vite: Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials
Large-Scale Cyberattack Targets Exposed Vite Servers to Steal Cloud Credentials
753
CRITICAL-2
VIT1789410399
Large-Scale Cyberattack Targets Exposed Vite Servers to Steal Cloud Credentials
In August 2026, security researchers at F5 detected a surge in automated attacks targeting internet-exposed Vite development servers, aiming to harvest AWS credentials, Azure access tokens, environment variables, and Infrastructure-as-Code (IaC) secrets. The campaign exploited CVE-2026-39364, a high-severity file-disclosure vulnerability in Vite versions 7.1.0–7.3.1 and 8.0.0–8.0.4, allowing unauthenticated attackers to bypass security controls and retrieve sensitive files.
F5’s honeypot sensors recorded 807 session-grouped attacks and 32,000 raw events in August alone a dramatic increase from just 1,732 Vite-related file-read events over the prior three months. Attackers leveraged the vulnerability by sending crafted requests to Vite’s internal `@fs` route, combining query-string bypasses (e.g., `?raw`, `?import&raw`), path traversal, and double-encoded separators to access restricted files. Targets included `.env` files, AWS credential directories, Azure `accessTokens.json`, Terraform state files, and `/proc/self/environ`, which exposes an application’s environment without requiring its absolute path.
The campaign’s infrastructure also tested older Vite access-control bypasses and probed for vulnerabilities in other frameworks, including CVE-2025-29927 (Next.js middleware bypass) and CVE-2025-31125 (a Known Exploited Vulnerability per CISA). Attackers used forged User-Agent strings (e.g., Googlebot, ClaudeBot) and spoofed X-Forwarded-For headers to evade detection, while most activity originated from Google Cloud Platform IPs (34.x, 35.x ranges). The U.S. saw the highest volume of attacks (17,297 events), followed by Belgium, the Netherlands, Singapore, Taiwan, and Japan.
Exposed Vite servers often misconfigured via `--host` flags, container port mappings, or cloud security-group errors remain prime targets. Successful exploitation could grant attackers API keys, database passwords, cloud access credentials, and IaC secrets, enabling broader cloud compromise. Organizations are advised to upgrade to Vite 7.3.2 or 8.0.5+, remove development servers from public networks, and audit logs for suspicious requests targeting sensitive files. Compromised credentials, including AWS keys and Azure tokens, should be revoked and rotated immediately.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
755
JUNE 2026
755
MAY 2026
756
APRIL 2026
756
MARCH 2026
756
FEBRUARY 2026
756
JANUARY 2026
756
DECEMBER 2025
756
NOVEMBER 2025
756
OCTOBER 2025
756
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for VSG ??
What was VSG's A.I Rankiteo Cyber Score in August 2026 ??
What was VSG's A.I Rankiteo Cyber Score in July 2026 ??
What was VSG's A.I Rankiteo Cyber Score in June 2026 ??
What was VSG's A.I Rankiteo Cyber Score in May 2026 ??
What was VSG's A.I Rankiteo Cyber Score in April 2026 ??
What was VSG's A.I Rankiteo Cyber Score in March 2026 ??
What was VSG's A.I Rankiteo Cyber Score in February 2026 ??
What was VSG's A.I Rankiteo Cyber Score in January 2026 ??
What was VSG's A.I Rankiteo Cyber Score in December 2025 ??
What was VSG's A.I Rankiteo Cyber Score in November 2025 ??
What was VSG's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on VSG's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with VSG ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view VSG's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?