Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Prime Day Air Fryer Deals: Shop Instant Pot, Ninja, and More

Prime Day Fitbit sale: Shop Inspire 3, Charge 6, and more

Dyson’s best Prime Day deals: discounts on Dyson V12 Detect Slim and Supersonic

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » New “Fuami” attacks cause ami name confusion for remote code execution
Celebrities

New “Fuami” attacks cause ami name confusion for remote code execution

By February 14, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

February 14, 2025Ravi LakshmananVulnerability / DevOps

Cybersecurity researchers have created a new type of name confusion attack called Whoami, which allows people to publish Amazon Machine Images (AMIs) with specific names that can obtain code execution within Amazon Web Services (AWS) accounts. It is disclosed.

“If executed at scale, this attack can be used to gain access to thousands of accounts,” Datadog Security Labs researcher Seth Art said in a report shared with Hacker News. . “The vulnerable patterns are found in many private and open source code repositories.”

At its heart, this attack is a subset of supply chain attacks that involves exposing malicious resources and tricking software that is misconfigured to use the wrong software in place of a legitimate counterpart. .

Cybersecurity

This attack takes advantage of the fact that AMIs can have an AMI referencing the AMI. This takes advantage of the virtual machine images used to boot up AWS elastic computing cloud (EC2) instances, community catalogs, and the fact that developers can omit to mention “-owner” “Attribute when searching for one via EC2: descriptionimages api.

Put another way, a name confusing attack requires that the victim meet the following three conditions when obtaining an AMI ID via the API –

Get the most recently created images from the returned list of matching images because I couldn’t specify either the name filter use, owner, owner ALIA, or owner and ID parameters (” most_recent = true”)

This leads to a scenario where an attacker can create a malicious AMI with a name that matches the pattern specified in the search criteria, allowing the threat actor to create an EC2 instance.

This gives the instance the Remote Code Execution (RCE) capability, allowing threat actors to initiate various post-exploitation actions.

All the attackers need is an AWS account to publish the background AMI to the public community AMI catalog and select a name that matches the AMIS that the target is looking for.

“The latter is very similar to dependency confusion attacks, whereas malicious resources are software dependencies (such as PIP packages), but with Whoami-name confusion attacks, there is a malicious resource is a virtual machine image,” Art said.

Datadog is vulnerable to public examples of code written in Python, Go, Go, Java, Terraform, Pulumi and Bash Shell, with around 1% of organizations being monitored by the company being affected by Woami attacks. He said he found it using criteria.

Following the responsible disclosure on September 16, 2024, the issue was addressed by Amazon three days later. When asked for comment, AWS told Hacker News it couldn’t find any evidence that the technique was abused in the wild.

“All AWS services operate as designed. Based on extensive log analysis and monitoring, our study shows that the techniques described in this study have no evidence of use by other parties. “We have confirmed that it is being carried out only by the authorized researchers themselves.”

Cybersecurity

“This technique can affect customers who obtain Amazon Machine Image (AMI) ID via EC2: explain the API without specifying the value of the owner. In December 2024, Introducing AMIS, a new account-wide setting that allows customers to limit discovery, and using AMIS within AWS accounts.

As of November last year, Hashicorp Terraform began issuing warnings to users if “most_recent = true” is used without owner filters for Terraform-provider-aws version 5.77.0. Warning diagnostics are expected to be upgraded to Error Effects Version 6.0.0.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleLazarus Group deploys MarStech1 JavaScript implants to target developer attacks
Next Article Meta will enter the AI ​​Humanoid Race with the launch of a new robotics division to compete with Tesla.

Related Posts

Zendaya styles her ‘damp bixie’ in Berlin

June 22, 2026

Hailey Bieber debuts Skims campaign with Everyday Cotton

June 22, 2026

Reese Witherspoon sports Chanel on ‘Elle’ promotional tour

June 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Prime Day Air Fryer Deals: Shop Instant Pot, Ninja, and More

Prime Day Fitbit sale: Shop Inspire 3, Charge 6, and more

Dyson’s best Prime Day deals: discounts on Dyson V12 Detect Slim and Supersonic

10+ Prime Day vacuum cleaner deals carefully selected by professional vacuum testers

Trending Posts

Beyoncé reveals how Blue Ivy influenced Jay-Z’s hair journey in new clip

June 22, 2026

Olivia Rodrigo explains why jealousy is often featured in her songs

June 22, 2026

Zendaya styles her ‘damp bixie’ in Berlin

June 22, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.