logo

IMDS Abused: Hunting Rare Behaviors to Uncover Exploits

ID: aba991ad-59f1-5360-a2b1-d073c27803dc

STIX ID: report--aba991ad-59f1-5360-a2b1-d073c27803dc

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2025-09-22

Date Updated: 2026-05-01

...
...

This report explains how attackers exploit application-level SSRF and misconfigurations to query cloud Instance Metadata Services (IMDS) and steal temporary credentials, describes a data-driven hunting approach that uncovered an in-the-wild pandoc zero-day (CVE-2025-51591) and a ClickHouse SSRF abuse case, and provides detection and mitigation guidance such as enforcing IMDSv2, applying least-privilege roles, and using runtime sensors and security graph analysis to detect anomalous IMDS usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.