Mitiga researchers disclose AWS Elastic IP hijacking vulnerability | Computer Weekly

General News

Summary

Mitiga threat researchers have identified what they describe as a new potential attack vector leveraging recently introduced functionality in Amazon Web Services (AWS) technology that has made changing Elastic IP ownership in AWS Elastic Compute Cloud (EC2) environments easier. Mitiga is an AWS partner, and provides software and services for security incident response and preparedness in cloud environments. Mitiga said the method “can expand the blast radius of an attack and allow further access to systems relying on IP allowlisting as their primary form of authentication or validation”. “The ‘hijacking an EIP’ scenario isn’t even shown as a technique in the MITRE ATT&CK knowledge base, which means this new technique can go ‘under the radar’.” Malicious actors could attach a stolen EIP to an EC2 instance in their own AWS account for purposes that include reaching a victim’s network endpoints, secured by a firewall that possesses an ingress rule which allows connections from the stolen IP. An EC2 instance is a virtual server in Amazons Elastic Compute Cloud for running applications on the AWS infrastructure.

Classifications

industries
No industries detected
applications
ERP & Process Management

AskAI Classifications

Labels
No AI classifications detected

Linked Companies