logo

Duping Cloud Functions: An emerging serverless attack vector

ID: 0b05bd6e-0473-51cc-b7ef-c43f10973840

STIX ID: report--0b05bd6e-0473-51cc-b7ef-c43f10973840

Feed Name: Cisco Talos

Threat Score
55/100

Date Published: 2025-05-20

Date Updated: 2026-04-27

Author: William Charles Gibson

...
...

Cisco Talos evaluates and extends Tenable’s findings about a GCP Cloud Functions / Cloud Build privilege-escalation vulnerability: Talos confirms Google patched the token-exfiltration vector but shows that attackers can adapt the technique by publishing malicious NPM packages and leveraging serverless function builds (GCP, AWS Lambda, Azure Functions) to perform environment enumeration and reconnaissance. The report documents prerequisites, emulation steps, enumeration commands (host, user, container, network discovery), and recommended mitigations including least-privilege service accounts, auditing IAM, verifying package integrity, alerting on function changes, and monitoring for exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.