Serverless still has an attack surface

A function that runs for two hundred milliseconds can still be injected into, over-permissioned and used to reach everything its role allows.

The short lifetime limits persistence, not impact. Event sources become inputs, so a message queue or a storage trigger is now an untrusted entry point. The model changes which risks apply; it does not produce an application with no risks.

More on Cloud resilience