cognitive cybersecurity intelligence

News and Analysis

Search

New “whoAMI” Attack Exploits AWS AMI Name Confusion for Remote Code Execution

Cybersecurity researchers have revealed a new name confusion attack called whoAMI. The flaw in Amazon Web Services (AWS) allows anyone who publishes an Amazon Machine Image (AMI) with a specific name to gain access to code execution within the AWS account of the intended target. If launched on a vast scale, the offensive could infiltrate thousands of accounts. The attack represents a subset of a supply chain attack and exploits a misconfiguration in the use of AMIs.

Source: thehackernews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts