Get a Demo
Under Attack?
A logo featuring a white symbol resembling an abstract letter inside a circular gradient shape, transitioning from orange to blue. The background is light with a dotted line dividing the circle horizontally. The upwind text appears in the top left corner.

Automatically Secure AWS Lambda Functions with Upwind

<br />
<b>Warning</b>:  Undefined variable $photo in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
<br />
<b>Warning</b>:  Trying to access array offset on value of type null in <b>/nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code</b> on line <b>24</b><br />
Joshua Burgin October 17, 2024

We are excited to announce support for AWS Lambda as a part of Upwind’s agentless Cloud Scanners.

Upwind’s protection for Lambda functions running on AWS can be seen throughout the Upwind platform, extending our proactive risk analysis and visibility across  your entire cloud infrastructure – from containers to VMs to serverless.

What are Lambda Functions?

Lambda functions, a key component of serverless architectures on AWS, allow developers to run code without provisioning or managing servers, leading to faster development cycles and cost savings. However, these benefits introduce unique challenges to managing security risks effectively.

Why are Lambda Functions Difficult to Secure?

Securing Lambda functions is a challenge due to their granular permissions model, dynamic execution environments, and the absence of persistent infrastructure typically found in VM or container-based architectures, making traditional security controls difficult to apply. Additionally, each Lambda function operates within a shared environment and requires separate permission controls for each individual Lambda function with AWS Identity and Access Management (IAM), which can lead to excessive permissions and resource exposure if IAM roles are misconfigured.

Screenshot-2024-10-15-at-6.10.13%E2%80%AFAM-1024x413



Lambda functions can also be difficult to secure due to their ephemeral nature, meaning they can be rapidly deployed and modified and are at higher risk of vulnerabilities. Monitoring and auditing logs for Lambda executions can also be more complex compared to traditional VM or container-based  environments, making it harder to detect unauthorized access or anomalous behavior.

Upwind’s Comprehensive Security for AWS Lambda Functions

Screenshot-2024-10-15-at-6.18.05%E2%80%AFAM-1024x583

Upwind’s agentless Cloud Scanners provide comprehensive security for Lambda functions, which can be seen across  the capabilities within the Upwind platform:

  • Vulnerability Management: Upwind scans for vulnerabilities in Lambda functions, which are shown in the Vulnerabilities tab.
  • Posture: Upwind scans for exposed secrets and misconfigurations related to Lambda IAM roles.
  • Threats: Upwind scans for malware impacting AWS Lambda functions, surfacing findings in the Threats tab.
  • Inventory: See comprehensive status & manage  the scanning of your Lambda environments  in the Inventory tab of the Upwind platform under “Upwind components,” and view all scans and their results. 
  • Identity Security: Managing all human and non-human identities and their permissions, including IAM roles and permissions for AWS Lambda functions.
Lambda-1024x699

Upwind’s comprehensive protection for Lambda functions provides you with increased visibility into Lambda functions, proactive risk management and prioritized  findings that are surfaced as a part of the Upwind platform. To learn more, schedule a demo.

Contents

Further Reading

ArgoCD repoURL XSS

ArgoCD repoURL XSS: How a Missing Scheme Check Becomes Cluster Takeover (CVE-2026-62341)

Executive Summary  CVE-2026-62341 is a stored cross-site scripting (XSS) vulnerability in ArgoCD [versions <= 3.4.6] that lets an attacker who can create or modify an Application persist a malicious repoURL, which then executes in an administrator's browser inside the ArgoCD origin. Because the payload rides the admin's authenticated session, and because ArgoCD's controller typically runs…
The Risk Isn't What You Prompt, It's What You Built.

The Risk Isn’t What You Prompt, It’s What You Built

Key Takeaways: Agentic AI security is an architecture problem, not a policy problem. Most organizations have adopted AI agents in the form of coding assistants, autonomous workflow tools, internal chatbots connected to production systems, but without establishing the foundational security frameworks those systems require. The adoption pressure is real. Telling your engineering team to stop…
Upwind is a Visionary Leader in Frost & Sullivan report

Upwind Named a Strong Visionary Leader in Frost & Sullivan’s 2026 Cloud/Application Runtime Security Radar

We're excited to share that Frost & Sullivan has recognized Upwind as a Strong Visionary Leader in the Frost Radar™: Cloud/Application Runtime Security, 2026. This recognition highlights the company's innovation, growth, and leadership in the emerging Cloud-Native Application Detection and Response (CNADR) market. For us, the recognition is meaningful not simply because of where Upwind…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS