whoAMI attack could allow remote code execution within AWS account
ID: ccd8596e-591e-5329-b4fe-0864b9ed98cb
STIX ID: report--ccd8596e-591e-5329-b4fe-0864b9ed98cb
Feed Name: Security Affairs
Datadog Security Labs disclosed a name‑confusion attack called whoAMI that allows an attacker to publish a malicious community AMI whose name causes it to be returned by automated AMI searches when victims omit owner filters; if selected, the AMI can execute arbitrary code in the victim's AWS account. The researchers produced a PoC with a backdoored AMI, estimate ~1% of organizations could be vulnerable at scale, and note that mitigations now exist (AWS Allowed AMIs and terraform/provider warnings).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
