Menu
Washingtoner
  • Home
  • Health
  • Books
  • Business
  • Music
  • Construction
  • Technology
  • Artificial Intelligence
  • Arts
Washingtoner

Cyberpion Reveals A Quarter of Fortune 500 Companies Have Exploitable Vulnerabilities in their External IT Network
Washingtoner/10132666

Trending...
  • Tacoma: Applications Now Being Accepted for three Positions on the Urban Design Board
  • Spokane: Community Resources Available to Those Impacted by Fires
  • Premier Expands Presence with New Bellevue Flexible Workspace Location
KIRKLAND, Wash. and TEL AVIV, Israel, Sept. 14, 2021 /PRNewswire/ -- Cyberpion, a cybersecurity pioneer in external attack surface management (EASM), today presented research showing that nearly three quarters of Fortune 500 companies' IT infrastructure exists outside their organization, a quarter of which was found to have a known vulnerability that threat actors could infiltrate to access sensitive employee or customer data.

Key research findings:
  • 73% of Fortune 500 companies' total IT infrastructure is external to the organization, of which 24% is considered at risk or has a known vulnerability
    • The total IT infrastructure includes the IT assets that are owned and operated by vendors the Fortune 500 enterprises incorporated into their online footprint
    • These IT assets include servers, cloud storage, CDNs, DNS (Domain Name Servers), email servers and other online elements
  • 71% of total cloud-based IT assets are external to the organization, of which 25% failed at least one security test
    • An example of cloud vulnerability includes cloud storage configured to allow anyone to read or write its contents
  • On average, a Fortune 500 company's infrastructure contains 126 different login pages for either customer or employee portals or services - the highest number was over 3,000
    • Nearly 10% of these login pages are considered insecure due to the transmission of unencrypted login data, or issues with SSL certificates, which helps ensure that the submission is being sent to the authorized destination
    • 30% allow transmission over HTTP
    • 12% have invalid certificates/encryption
    • Hackers exploiting these logins could access a wealth of sensitive employee or customer data
  • Fortune 500 organizations connect to an average of 951 cloud assets, of which nearly 5% are vulnerable to severe abuse
    • For example, a misconfigured AWS bucket could allow hackers to read or overwrite the data which could be customer PII or application code
    • The largest exposure was well over 30K cloud assets

Cyberpion collected these results by performing a cursory single-pass scan of the public and internet-facing assets of every Fortune 500 company in the first half of 2021.

More on Washingtoner
  • UK Financial Ltd Makes History: Chainlink CRE Circulating Supply Verification Goes Live Across Its Complete Ecosystem Of Nine Exchange-Traded Tokens
  • International Rights Groups Raise Alarm Over Freedom of Religion and Expression in South Korea
  • WDTA Hosts Landmark DWC Seattle AI Summit in Bellevue, Bridging AI Governance and Innovation
  • City of Spokane Staff on Hand at Disaster Assistance Center
  • Tacoma: Homicide Investigation – 2100 block of N 30th St

According to Gartner1, "EASM is an emerging concept that is growing quickly in terms of awareness within the security vendor community but at a slower pace within end-user organizations...They help security professionals identify exposed vulnerabilities from known and unknown enterprise assets and prioritize the most critical issues to be tackled...EASM should be part of a broader vulnerability and threat management effort aimed at discovering and managing internal- and external-facing assets and their potential vulnerabilities."

Traditional third-party risk management solutions have focused exclusively on the vendors and the IT infrastructures that are directly connected to the enterprise. This approach ignores the true scale of the problem and represents only the tip of the iceberg. Third-party vendors have also adopted a distributed IT infrastructure, and have built their applications and services using their own vendors and third-parties. Those in turn build their solutions upon even more partners. This extensive ecosystem creates an external attack surface that is uniquely appealing to hackers to attack, and extremely complicated for enterprises to manage securely.

Hackers are finding it easier to takeover or exploit the vulnerabilities in the third-party assets within the enterprise's ecosystem in order to carry out attacks such as: malicious code injection (Magecart-style attacks), DNS hijacks, or abusing the branded assets of an enterprise. These breaches ultimately lead to data loss, brand reputation damage, and stolen customer data for the enterprise.

"Security teams often can't effectively defend against attacks stemming from third-parties because they lack visibility into the total inventory and volume of assets they are connected to," said Cyberpion CEO Nethanel Gelertner. "They are unaware of the exposure to these external vulnerabilities, and can't identify and mitigate against these risks. In addition, the growth of these interconnected assets continues to explode due to trends in cloud-first architectures and digital transformation initiatives, meaning that assessing and protecting the attack surface has become even more challenging over time."

More on Washingtoner
  • The City's Most Elegant Open-Air Dinner Party Returns September 12, 2026
  • Spokane: Incorrect Info Regarding Downgraded Evacuation Status on Popular App
  • FDA Clears Major Regulatory Hurdle as Preservative-Free Ketamine Program Moves Within Reach of Commercialization: NRx Pharmaceuticals: (NAS DAQ: NRXP)
  • Autonomous Robotics Platform Expansion as Public Market Debut is Very Close: MBody AI Corp. (N A S D A Q: MBAI)
  • Tacoma Voters Approve Connect Tacoma: Safe Streets and Sidewalks Levy (Proposition 1)

About Cyberpion

Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets that form an external attack surface. Knowing how your organization is vulnerable, where those threats come from, and what infrastructures are at risk, is critical to preventing an attack before it happens. Cyberpion helps organizations mitigate these advanced threats by continuously monitoring, discovering, and assessing the threat vectors present throughout online ecosystems that exist outside the traditional security perimeter. With an R&D team based in Israel, the company is funded by leading cybersecurity venture capitalists. To learn more, visit cyberpion.com.

For more information, please contact:
Josh Turner
Si14 Global Communications
josh.[email protected]

1 Gartner, "Emerging Technologies: Critical Insights for External Attack Surface Management" by Ruggero Contu, Elizabeth Kim and Mark Wah, March 19, 2021

SOURCE Cyberpion
Show All News | Disclaimer | Report Violation

0 Comments
1000 characters max.

Latest on Washingtoner
  • Portalz Publishes FES World First Architecture Introducing a New Cryptographic Platform
  • ExtraCarry Sponsors Threat Response's Defensive Tactics Camp for Third Consecutive Year
  • ExtraCarry Sponsors the World Revolver Championship
  • Tacoma City Council Funds Pilot with St. Leo Food Connection to Expand Food Access at Tacoma Public Library
  • Tacoma: Applications Now Being Accepted for three Positions on the Urban Design Board
  • Spokane: Wildfire and Insurance Informational Session
  • Premier Expands Presence with New Bellevue Flexible Workspace Location
  • Haven Treatment Center In-Network with MODA Health, Expanding Access to Behavioral Health
  • Cellofest Brings Free Cello Concerts and Community Events to Bethany Beach August 5–16
  • Blue Sky Capital Strategies, LLC awarded Leasing and Financial Services agreement with Premier Inc
  • Michael M. Thomas Expands Executive Leadership Across Central India Outreach and Royal Trinity School
  • Northeast Airlines and Travel, Inc. Initiates FAA Part 121 Certification for Boeing 737-800 Freighter Cargo Operations
  • Walker's Realty and North Jersey Properties Introduce Extraordinary Luxury Estate for Rent in West Orange, New Jersey
  • Extreme Heat Strains Home Appliances: Appliance EMT Offers "Summer Rescue" Relief
  • Independent West Texas Metal Multi-Instrumentalist & Producer. "MAD CHAD™" Russell Surpasses 1.9 Million Project Interactions Via DFGS Productions
  • No Download Needed: Goosechase Adds Browser Play to Every Experience
  • iCustoms launches iWarehouse, an AI bonded warehouse platform for customs and excise storage
  • Spokane: City Council Members Commends Unified Wildfire Response
  • National Night Out in Spokane Cancelled Due to Wildfire Conditions
  • Haven Treatment Center Achieves IMD Certification, Expanding Access to Residential Care
_catLbl0 _catLbl1

Popular on Washingtoner

  • Martin A. Sumichrast Joins Hawkeye Systems, Inc. as Chairman of the Board - 113
  • Qscription Technologies Appoints Radiology Industry Veteran Elliot Silverman to Advisory Board - 103
  • Studica Robotics Supports Robotics Training Camp for WorldSkills Shanghai 2026
  • Spokane: Mayor Brown Joins 10th Bloomberg Harvard City Leadership Initiative Class to Strengthen Local Government and Advance Resident Priorities
  • Northeast Airlines Launches New Asset Management Group
  • Boston Industrial Solutions Launches New Citrine® SA1-370 Silicone Glue for Permanent Adhesion
  • From the Racetrack to the Boardroom: Aston Martin and Aramco Formula One Partnership Accelerates Circle8 Group: (N A S D A Q: CIRC)
  • Where Is Your Faith The Movie and Sountrack
  • Mr. Hospital Bed Helps Home Care Buyers Find the Right Hospital Bed
  • DBF Viewer 2000 v9.25 Adds Command-Line Index Tag Removal

Similar on Washingtoner

  • RAS AP Consulting Expands Managed AP Governance™ Ecosystem, Launches Trademark Process, and Secures IFOL Speaker Invitation
  • UK Financial Ltd Makes History: Chainlink CRE Circulating Supply Verification Goes Live Across Its Complete Ecosystem Of Nine Exchange-Traded Tokens
  • FDA Clears Major Regulatory Hurdle as Preservative-Free Ketamine Program Moves Within Reach of Commercialization: NRx Pharmaceuticals: (NAS DAQ: NRXP)
  • Autonomous Robotics Platform Expansion as Public Market Debut is Very Close: MBody AI Corp. (N A S D A Q: MBAI)
  • Silicon Box Ships 500M Units at High Yield, Expands Production Capacity for Panel-Level Packaging
  • Why Baton Rouge's Humid Climate Can Contribute to Carpenter Ant Damage — J&J Exterminating Explains How to Protect Your Home
  • Expanding Beyond Space as New Drone Market Opportunities Accelerate Growth: Ascent Solar Technologies (N A S D A Q: ASTI)
  • Lauren Merrell, Dale Sorensen Real Estate, announces price improvement for an extraordinary island retreat
  • Qustone Launches Human-Centered Professional Network
  • Portalz Publishes FES World First Architecture Introducing a New Cryptographic Platform
Copyright © 2026 washingtoner.com | Terms of Service | Privacy Policy | Contact Us | Contribute