//
sign in
Profile
by @danabra.mov
Profile
by @dansshadow.bsky.social
Profile
by @jimpick.com
AviHandle
by @danabra.mov
AviHandle
by @dansshadow.bsky.social
AviHandle
by @katherine.computer
EventsList
by @katherine.computer
ProfileHeader
by @dansshadow.bsky.social
ProfileHeader
by @danabra.mov
ProfileMedia
by @danabra.mov
ProfilePlays
by @danabra.mov
ProfilePosts
by @danabra.mov
ProfilePosts
by @dansshadow.bsky.social
ProfileReplies
by @danabra.mov
Record
by @atsui.org
Skircle
by @danabra.mov
StreamPlacePlaylist
by @katherine.computer
+ new component
ProfilePosts









Loading...
When I first started reading this I though,t “is this really news, this issue has been around for years…” but then it gets interesting - kudos to the researchers on this one!
Feb 12, 2025
Matt J
The February edition of the Datadog Security Digest is out! securitylabs.datadoghq.com/newsletters/... featuring @sethsec.bsky.social, @mccune.org.uk, @karimscloud.bsky.social, @jcfarris.bsky.social, and more
fwd:cloudsec is around the corner! Don't miss these 3 talks from Datadog researchers Seth Sec, Katie Knowles, Greg Foss, and Anthony Randazzo. fwdcloudsec.org/conference/n... @sethsec.bsky.social @siigil.bsky.social @gregfoss.com
Introducing Pathfinding.cloud, a library of privilege escalation paths in AWS securitylabs.datadoghq.com/articles/int... by @sethsec.bsky.social
The Datadog Security Digest is a monthly, practitioner-focused newsletter. Don't miss our February edition going live tomorrow! securitylabs.datadoghq.com/newsletters/...
I’m excited to share our research on the “whoAMI” attack. We discovered that AWS customers pulling AMI IDs insecurely could accidentally use malicious images instead of the legitimate ones— leading to remote code execution. securitylabs.datadoghq.com/articles/who...
whoAMI attacks give hackers code execution on Amazon EC2 instances
The July edition of the Datadog Security Digest is out! securitylabs.datadoghq.com/newsletters/... • Cloud image investigator by @sethsec.bsky.social • Our top picks for Black Hat / DEF CON • A benchmark for LLM coding accuracy and security • Malicious Homebrew installation campaign .. and more
Feb 13, 2025
6mo
Jun 27, 2025
I’m excited to share our research on the “whoAMI” attack. We discovered that AWS customers pulling AMI IDs insecurely could accidentally use malicious images instead of the legitimate ones— leading to remote code execution. securitylabs.datadoghq.com/articles/who...
Need to hack thousands of AWS customers? What about on internal AWS systems? Datadog Security Research found that a number of tools, including one published by AWS, are susceptible to name confusion attacks, leading to RCE in vulnerable environments! securitylabs.datadoghq.com/articles/who...
Feb 26, 2025
Feb 27, 2025
We discovered a pattern in the way many projects retrieve Amazon Machine Images (AMIs), allowing attackers to publish AMIs with specially crafted names and gain code execution within vulnerable accounts. securitylabs.datadoghq.com/articles/who... by @sethsec.bsky.social
10mo
Feb 12, 2025
Feb 12, 2025
Feb 12, 2025
Feb 12, 2025
Security researchers discovered a name confusion attack that allows access to an Amazon Web Services account to anyone that publishes an Amazon Machine Image (AMI) with a specific name.
www.bleepingcomputer.com
whoAMI attacks give hackers code execution on Amazon EC2 instances
The whoAMI name confusion attack, modern phishing tactics, and K8s network security fundamentals | Datadog Security Labs
This February edition of the Datadog Security Digest dives into the
securitylabs.datadoghq.com
This month’s digest covers Hacker Summer Camp prep, a new cloud image investigator, and supply-chain vulnerabilities associated with the Open VSX Registry.
securitylabs.datadoghq.com
Detailing the discovery and impact of the whoAMI cloud image name confusion attack, which could allow attackers to execute code within AWS accounts due to a vulnerable pattern in AMI retrieval.
securitylabs.datadoghq.com
Preparing for Hacker Summer Camp and a new cloud image investigator | Datadog Security Labs
whoAMI: A cloud image name confusion attack | Datadog Security Labs
Detailing the discovery and impact of the whoAMI cloud image name confusion attack, which could allow attackers to execute code within AWS accounts due to a vulnerable pattern in AMI retrieval.
securitylabs.datadoghq.com
whoAMI: A cloud image name confusion attack | Datadog Security Labs
Detailing the discovery and impact of the whoAMI cloud image name confusion attack, which could allow attackers to execute code within AWS accounts due to a vulnerable pattern in AMI retrieval.
securitylabs.datadoghq.com
whoAMI: A cloud image name confusion attack | Datadog Security Labs
Detailing the discovery and impact of the whoAMI cloud image name confusion attack, which could allow attackers to execute code within AWS accounts due to a vulnerable pattern in AMI retrieval.
securitylabs.datadoghq.com
whoAMI: A cloud image name confusion attack | Datadog Security Labs
Datadog Security Labs
Datadog Security Labs
Datadog Security Labs
Datadog Security Labs
Datadog Security Labs
Datadog Security Labs
InfoSec
Seth Art
Seth Art
Nick Frichette