logo

whoAMI: A cloud image name confusion attack

ID: 76e7a20c-cdf7-5817-b009-7b95f8679861

STIX ID: report--76e7a20c-cdf7-5817-b009-7b95f8679861

Feed Name: Datadog Security Labs

Threat Score
65/100

Date Published: 2025-02-12

Date Updated: 2026-04-27

...
...

### Executive Summary Datadog Security Labs discovered and responsibly disclosed a 'whoAMI' name confusion vulnerability in which systems that call ec2:DescribeImages filtered only by name (and not by owner) can be tricked into using attacker-published AMIs, enabling arbitrary code execution; they demonstrated the issue across Terraform, CLI, and SDKs, found real-world vulnerable code, coordinated a fix with AWS (including the new Allowed AMIs guardrail), and published detection and remediation tools and rules (whoAMI-scanner, Semgrep, Cloud SIEM rules).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.