Permissive Execution Permissions were Granted to Lambda Function
Medium
🕓 Last Seen 04-08-2026 · 4:00:22 PM|🗂 cyngular_client_1👤 Unassigned ▾● New ▾
View all IOC's
Enriched, correlated and triaged by the agent squad.
3 min
Time to resolution
0
Analyst touches
1
Consoles to pivot
6
Agents working
✦AI Summary Mesh live · agents collaborating1,284 inter-agent messages today
Cyngular uncovered a cloud threat where permissive execution permissions were granted to a Lambda function in AWS. The change was initiated by arn:aws:sts::528757810539:assumed-role/MaliciousEC2Role using the action AddPermission20150331v2 on arn:aws:lambda:us-west-2:…:MaliciousLambdaFunc, granting external account 248189932415 the right to invoke it. On its own the event reads Medium — but correlated with a leaked GitHub key, an impossible-travel Okta login and a downstream S3 policy change, the squad rates the overall campaign Critical: an external actor establishing persistence to stage data exfiltration.
How the squad worked this — one brain, six agents· click any agent to see just its activity