- Engineer — Plan: Mandiant assessments routinely find unauthenticated Cloud Run/Functions exposed to the internet; audit your serverless inventory for missing auth controls and apply the hardening patterns (least-privilege service accounts, input validation, network egress restrictions) this quarter. No active exploitation signals elevate this to Act.
- SOC/IR — Learn: The LFI/RFI and command-injection paths described could inform detection logic for serverless workloads, but there are no IOCs, no named campaign, and no novel TTPs here — no immediate hunt or rule-writing required.
- Leader — Skip