IMDS Abused: Hunting Rare Behaviors to Uncover Exploits
ID: aba991ad-59f1-5360-a2b1-d073c27803dc
STIX ID: report--aba991ad-59f1-5360-a2b1-d073c27803dc
Feed Name: Wiz Blog
This report explains how attackers exploit application-level SSRF and misconfigurations to query cloud Instance Metadata Services (IMDS) and steal temporary credentials, describes a data-driven hunting approach that uncovered an in-the-wild pandoc zero-day (CVE-2025-51591) and a ClickHouse SSRF abuse case, and provides detection and mitigation guidance such as enforcing IMDSv2, applying least-privilege roles, and using runtime sensors and security graph analysis to detect anomalous IMDS usage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
