logo

whoAMI attack could allow remote code execution within AWS account

ID: ccd8596e-591e-5329-b4fe-0864b9ed98cb

STIX ID: report--ccd8596e-591e-5329-b4fe-0864b9ed98cb

Feed Name: Security Affairs

Threat Score
65/100

Date Published: 2025-02-17

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Datadog Security Labs disclosed a name‑confusion attack called whoAMI that allows an attacker to publish a malicious community AMI whose name causes it to be returned by automated AMI searches when victims omit owner filters; if selected, the AMI can execute arbitrary code in the victim's AWS account. The researchers produced a PoC with a backdoored AMI, estimate ~1% of organizations could be vulnerable at scale, and note that mitigations now exist (AWS Allowed AMIs and terraform/provider warnings).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.