whoAMI: A cloud image name confusion attack
ID: 76e7a20c-cdf7-5817-b009-7b95f8679861
STIX ID: report--76e7a20c-cdf7-5817-b009-7b95f8679861
Feed Name: Datadog Security Labs
### Executive Summary Datadog Security Labs discovered and responsibly disclosed a 'whoAMI' name confusion vulnerability in which systems that call ec2:DescribeImages filtered only by name (and not by owner) can be tricked into using attacker-published AMIs, enabling arbitrary code execution; they demonstrated the issue across Terraform, CLI, and SDKs, found real-world vulnerable code, coordinated a fix with AWS (including the new Allowed AMIs guardrail), and published detection and remediation tools and rules (whoAMI-scanner, Semgrep, Cloud SIEM rules).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
