whoAMI attacks give hackers code execution on Amazon EC2 instances
ID: df777db6-3353-5e34-b894-64ac37444d67
STIX ID: report--df777db6-3353-5e34-b894-64ac37444d67
Feed Name: Bleeping Computer
Security researchers disclosed the whoAMI attack, a name‑confusion vulnerability in AWS AMI selection that lets an attacker publish a malicious public AMI with a trusted-like name and obtain code execution when victim systems select it (commonly via ec2:DescribeImages without owner filters or tools using most_recent=true). Amazon patched the platform and added an 'Allowed AMIs' control; DataDog provided detection tooling and reported ~1% of monitored organizations remain vulnerable due to unpatched customer code and unsafe AMI selection patterns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
