INTEL_REPORT
Mandiant / Google Threat Intelligence Blog · published 7/15/2026, 2:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
The Risk of Exposed Cloud Functions and How to Harden Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remote File Inclusion (LFI/RF…
https://cloud.google.com/blog/topics/threat-intelligence/exposed-cloud-functions-harden
sha256:03914a17b52617f275aed5c99b9135c00f820b82f1833a6d50d2b28e83423fe0
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| request.args |
| Open → |
| domain | resp.read | Open → |
| domain | cloudrun01-abc.europe-west3.run.app | Open → |
| domain | go.mod | Open → |
| domain | cloudrun02-abc.europe-west3.run.app | Open → |
| domain | secretmanager.secretaccessor | Open → |
| domain | exampleabc01.com | Open → |
| url | https://cloudrun01-abc.europe-west3.run.app/ | Open → |
| url | https://cloudrun02-abc.europe-west3.run.app/ | Open → |
| url | http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token | Open → |
| url | https://exampleabc01.com | Open → |