New “whoAMI” Attack Exploits AWS AMI Name Confusion for Remote Code Execution
A new kind of name confusion attack known as whoAMI has been revealed by cybersecurity experts. It enables code execution within an Amazon Web Services (AWS) account for anyone who uploads an Amazon Machine Image (AMI) with a certain name.
Seth Art, a researcher at Datadog Security Labs, told The Hacker News that if the assault were carried out on a large scale, it might be used to access thousands of accounts. Numerous open source and private code repositories include the vulnerable pattern.
The method essentially consists of uploading a harmful resource and deceiving misconfigured software into using it in place of the genuine counterpart read more about New "whoAMI" Attack Exploits AWS AMI Name Confusion for Remote Code Execution.
Get up to date on the latest cybersecurity new...

