Menu
Washingtoner
  • Home
  • Business
  • Construction
  • Technology
  • Arts
  • Health
  • Property
  • Software
  • Real Estate
Washingtoner

Cyberpion Reveals A Quarter of Fortune 500 Companies Have Exploitable Vulnerabilities in their External IT Network
Washingtoner/10132666

Trending...
  • Pyro Marketing Opens New Digital Marketing Company to Power Growth for Fitness and Ecommerce Brands
  • LIB and Nidec Rejoin Forces for Giant TH-0098 Temperature Humidity Test Chamber
  • Alaska Air Group announces webcast of second-quarter 2025 financial results
KIRKLAND, Wash. and TEL AVIV, Israel, Sept. 14, 2021 /PRNewswire/ -- Cyberpion, a cybersecurity pioneer in external attack surface management (EASM), today presented research showing that nearly three quarters of Fortune 500 companies' IT infrastructure exists outside their organization, a quarter of which was found to have a known vulnerability that threat actors could infiltrate to access sensitive employee or customer data.

Key research findings:
  • 73% of Fortune 500 companies' total IT infrastructure is external to the organization, of which 24% is considered at risk or has a known vulnerability
    • The total IT infrastructure includes the IT assets that are owned and operated by vendors the Fortune 500 enterprises incorporated into their online footprint
    • These IT assets include servers, cloud storage, CDNs, DNS (Domain Name Servers), email servers and other online elements
  • 71% of total cloud-based IT assets are external to the organization, of which 25% failed at least one security test
    • An example of cloud vulnerability includes cloud storage configured to allow anyone to read or write its contents
  • On average, a Fortune 500 company's infrastructure contains 126 different login pages for either customer or employee portals or services - the highest number was over 3,000
    • Nearly 10% of these login pages are considered insecure due to the transmission of unencrypted login data, or issues with SSL certificates, which helps ensure that the submission is being sent to the authorized destination
    • 30% allow transmission over HTTP
    • 12% have invalid certificates/encryption
    • Hackers exploiting these logins could access a wealth of sensitive employee or customer data
  • Fortune 500 organizations connect to an average of 951 cloud assets, of which nearly 5% are vulnerable to severe abuse
    • For example, a misconfigured AWS bucket could allow hackers to read or overwrite the data which could be customer PII or application code
    • The largest exposure was well over 30K cloud assets

Cyberpion collected these results by performing a cursory single-pass scan of the public and internet-facing assets of every Fortune 500 company in the first half of 2021.

More on Washingtoner
  • ICAST 2025: The Crystal-Clear Revolution Begins at Booth #3233
  • Brindle Pet Supplies Now Carries Badlands Ranch Dog Food in Canada
  • $10 Million Allocated to Establish Crypto Treasury Focused on High Value Ethereum (ETH) & Bitcoin (BTC) as Long-Term Holdings for Cybersecurity Leader
  • Arcadis welcomes transportation leader Greg Spotts to advance mobility in Seattle and California
  • Cummings Graduate Institute for Behavioral Health Studies Celebrates New DBH Graduates

According to Gartner1, "EASM is an emerging concept that is growing quickly in terms of awareness within the security vendor community but at a slower pace within end-user organizations...They help security professionals identify exposed vulnerabilities from known and unknown enterprise assets and prioritize the most critical issues to be tackled...EASM should be part of a broader vulnerability and threat management effort aimed at discovering and managing internal- and external-facing assets and their potential vulnerabilities."

Traditional third-party risk management solutions have focused exclusively on the vendors and the IT infrastructures that are directly connected to the enterprise. This approach ignores the true scale of the problem and represents only the tip of the iceberg. Third-party vendors have also adopted a distributed IT infrastructure, and have built their applications and services using their own vendors and third-parties. Those in turn build their solutions upon even more partners. This extensive ecosystem creates an external attack surface that is uniquely appealing to hackers to attack, and extremely complicated for enterprises to manage securely.

Hackers are finding it easier to takeover or exploit the vulnerabilities in the third-party assets within the enterprise's ecosystem in order to carry out attacks such as: malicious code injection (Magecart-style attacks), DNS hijacks, or abusing the branded assets of an enterprise. These breaches ultimately lead to data loss, brand reputation damage, and stolen customer data for the enterprise.

"Security teams often can't effectively defend against attacks stemming from third-parties because they lack visibility into the total inventory and volume of assets they are connected to," said Cyberpion CEO Nethanel Gelertner. "They are unaware of the exposure to these external vulnerabilities, and can't identify and mitigate against these risks. In addition, the growth of these interconnected assets continues to explode due to trends in cloud-first architectures and digital transformation initiatives, meaning that assessing and protecting the attack surface has become even more challenging over time."

More on Washingtoner
  • $100 to $200 Million Equity Agreement with Top Digital Advisor Bitwise to Power Major Digital Asset Initiative for Bitcoin and Solana: OFA Group
  • New Collaboration Launches Corporate ESG Solution for Responsible Decommissioning and Transparent Reporting
  • SlickCashLoan Launches Free Loan Calculator to Help You Plan Monthly Payments
  • TikTok Star ArcadeFriends Attempts 24-Hour Claw Machine Marathon at Lucky Puppy Arcade in Las Vegas
  • Pyro Marketing Launches New Website to Accelerate Growth for Fitness Brands

About Cyberpion

Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets that form an external attack surface. Knowing how your organization is vulnerable, where those threats come from, and what infrastructures are at risk, is critical to preventing an attack before it happens. Cyberpion helps organizations mitigate these advanced threats by continuously monitoring, discovering, and assessing the threat vectors present throughout online ecosystems that exist outside the traditional security perimeter. With an R&D team based in Israel, the company is funded by leading cybersecurity venture capitalists. To learn more, visit cyberpion.com.

For more information, please contact:
Josh Turner
Si14 Global Communications
josh.[email protected]

1 Gartner, "Emerging Technologies: Critical Insights for External Attack Surface Management" by Ruggero Contu, Elizabeth Kim and Mark Wah, March 19, 2021

SOURCE Cyberpion
Filed Under: Business

Show All News | Report Violation

0 Comments
1000 characters max.

Latest on Washingtoner
  • Easton & Easton, LLP Files Suit Against The Dwelling Place Anaheim & Vineyard USA Over Abuse Allegations
  • AI Visibility: The Key to Beating Google's AI Overviews and Regaining Traffic
  • Stuck Doing Math or Figuring Out Life's Numbers? Calculator.now Makes It Stupidly Simple
  • Spokane: Mayor Brown Urges Federal Lawmakers to Save the Community Development Block Grant (CDBG) Program
  • Colbert Packaging Announces WBENC Recognition
  • DivX Empowers Media Enthusiasts with Free Expert Guides for Advanced MP4 Management
  • Assent Expands Executive Team to Accelerate Global Growth & Innovation
  • The World's Largest Green Economic Revolution Emerges as Nature, Tech, and Finance Converge
  • Vinnetwork Unveils Decentralized AI Platform with Vinnetwork(VIN) Token to Challenge Tech Giants' Data Monopoly
  • Centennial Flyers to Become Colorado's First Launch Customer for All-Electric B23 Energic Aircraft
  • Spokane Firefighters Battle 15 Suspicious Fires in 36 Hours
  • Pyro Marketing Opens New Digital Marketing Company to Power Growth for Fitness and Ecommerce Brands
  • Dr. John Salerno of Salerno Wellness Introduces Their New Full Body Capsule for Advanced LED Light Therapy Patient Treatments
  • Alaska Air Group announces webcast of second-quarter 2025 financial results
  • $14M Expansion Deal with Famed David Lloyd Highlights Rebrand of Sports, Entertainment and Gaming Innovation by AI Driven, Online Fan Engagement Co
  • Heartfelt Dreams Foundation Launches Campaign to Build CHD Hospital
  • Radarsign Tackles Intersection Safety with Launch of Grid-Free Solar LED Stop Sign
  • Miami Real Estate Agent Drastically Increases Interest In Homes
  • Adostics & Genmega Announce the Introduction of A-POD
  • Erie Home Celebrates 100th Location, Cementing Coast-to-Coast Footprint
_catLbl0 _catLbl1

Popular on Washingtoner

  • ASI Accelerates iMISĀ® Innovation by Acquiring CSI's Product Suite and Expert Team - 220
  • Keebos Launches New Universal Pearl Strap That Attaches to Any Phone Case - 208
  • Integris Composites Joins Paris Air Show at USA Pavilion - 189
  • Sploot Vets and DeepScan Launch Exclusive Regional U.S. Partnership to Bring Breakthrough Pet DNA Test to Market - 145
  • Evluma and LED Roadway Lighting Ltd. Join Forces to Drive Innovation - 140
  • purelyIV Blog Named One of the Top 45 IV Therapy Blogs by Feedspot - 129
  • GMO Miner: Creating a simple, efficient and reliable new cloud mining experience - 126
  • Exciting News: Pivotal Health Solutions Acquires Revolutionary Portable Parallel Bars - 122
  • Pregis Shares 2024 Sustainability Report Highlighting Progress in Circular Product Innovation, Emissions Accountability, and Global Impact - 121
  • High Profile Gateway Race Events With Strong Brand Exposure Plus Sponsorship in Female Motorsports; $100 Million Financing Unlocked: Lottery.com - 111

Similar on Washingtoner

  • Hire a Business Plan Writer: What to Expect and Why It's Worth It
  • Fastest Growing Staffings Firms
  • Inframark Continues to Build Its Community Management Capabilities and Multi-Disciplinary Presence in Arizona
  • $10 Million Allocated to Establish Crypto Treasury Focused on High Value Ethereum (ETH) & Bitcoin (BTC) as Long-Term Holdings for Cybersecurity Leader
  • Arcadis welcomes transportation leader Greg Spotts to advance mobility in Seattle and California
  • $100 to $200 Million Equity Agreement with Top Digital Advisor Bitwise to Power Major Digital Asset Initiative for Bitcoin and Solana: OFA Group
  • Santa Monica Businesses Push Back on Bus Stop Relocation That Threatens Access and Safety
  • The Blue Luna Encourages Local Schools to Take Steps to Enhance Safety for Students and Staff
  • Smart Resnse Unveils Smart Resnse(SRMS) Token-Powered AI Orchestration Platform to Revolutionize Multi-Billion Dollar Market
  • Cover Girl Finalist Teisha Mechetti Questions Legitimacy of Inked Originals Competition, Demands Transparency
Copyright © 2025 washingtoner.com | Terms of Service | Privacy Policy | Contact Us | Contribute