The false sense of security in serverless architectures
Serverless removes servers to manage, it does not remove risk. We debunk common myths and get practical: excessive permissions, exposed endpoints, event injection, vulnerable dependencies, and poorly managed secrets in AWS Lambda, Azure Functions, and GCP Cloud Functions, as well as how attackers pivot from a compromised function and which quick wins to apply in production.