CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Simple Scans for Cloud Metadata Service

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4709

As cited

Copy frozen at (site build).

vulnerabilities

Simple Scans for Cloud Metadata Service

Cloud providers expose a metadata service at 169.254.169.254 that allows virtual machines to retrieve machine-specific data, including IAM credentials and service account tokens. Widespread generic scans are attempting to exploit server-side request forgery (SSRF) vulnerabilities to access this service, following notable breaches like Capital One that leveraged metadata service exploitation. Amazon implemented IMDSv2 to mitigate this attack vector by requiring additional headers beyond simple GET requests.

Why it matters: Practitioners managing cloud infrastructure should verify that IMDSv2 is enforced and that SSRF protections are in place on all endpoints, as attackers are actively scanning for metadata service access across the internet.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary