While each of the above points are mostly quite factual, I don't personally find any of them to be restricting. We run a mixture of stateless and stateful services and serverless is suitable for the stateless ones.
The original problems for network security being solved by running functions in a VPC and secure connections to databases and even connection pools makes pretty much everything work.