Menu
Washingtoner
  • Home
  • Financial
  • Home
  • Technology
  • Education
  • Business
  • Services
  • Non-profit
  • Construction
Washingtoner

Cyberpion Reveals A Quarter of Fortune 500 Companies Have Exploitable Vulnerabilities in their External IT Network
Washingtoner/10132666

Trending...
  • Max Tucci Makes His Highly-Anticipated Debut On QVC—unveiling A Bespoke Luxury Chocolate Collection Inspired By 100 Years Of Tucci Hospitality
  • City of Tacoma Offers Virtual Workshop for Organizations New to Local Affordable Housing Development Funding Application Process
  • Spokane Police Department Continues To Bolster The Neighborhood Resource Officer Program
KIRKLAND, Wash. and TEL AVIV, Israel, Sept. 14, 2021 /PRNewswire/ -- Cyberpion, a cybersecurity pioneer in external attack surface management (EASM), today presented research showing that nearly three quarters of Fortune 500 companies' IT infrastructure exists outside their organization, a quarter of which was found to have a known vulnerability that threat actors could infiltrate to access sensitive employee or customer data.

Key research findings:
  • 73% of Fortune 500 companies' total IT infrastructure is external to the organization, of which 24% is considered at risk or has a known vulnerability
    • The total IT infrastructure includes the IT assets that are owned and operated by vendors the Fortune 500 enterprises incorporated into their online footprint
    • These IT assets include servers, cloud storage, CDNs, DNS (Domain Name Servers), email servers and other online elements
  • 71% of total cloud-based IT assets are external to the organization, of which 25% failed at least one security test
    • An example of cloud vulnerability includes cloud storage configured to allow anyone to read or write its contents
  • On average, a Fortune 500 company's infrastructure contains 126 different login pages for either customer or employee portals or services - the highest number was over 3,000
    • Nearly 10% of these login pages are considered insecure due to the transmission of unencrypted login data, or issues with SSL certificates, which helps ensure that the submission is being sent to the authorized destination
    • 30% allow transmission over HTTP
    • 12% have invalid certificates/encryption
    • Hackers exploiting these logins could access a wealth of sensitive employee or customer data
  • Fortune 500 organizations connect to an average of 951 cloud assets, of which nearly 5% are vulnerable to severe abuse
    • For example, a misconfigured AWS bucket could allow hackers to read or overwrite the data which could be customer PII or application code
    • The largest exposure was well over 30K cloud assets

Cyberpion collected these results by performing a cursory single-pass scan of the public and internet-facing assets of every Fortune 500 company in the first half of 2021.

More on Washingtoner
  • HELM Audio™ Partners with PQCrypto to Future-Proof Children's Hearing and Safety Data Using Post-Quantum Cryptography
  • Wala Blegay to Announce Run for Congress in Maryland's 5th District on Feb. 4
  • Luxury Lake-View Home Launches in Kissimmee's Bellalago community, Offering Privacy, Space, and Florida Resort-Style Living
  • Sleep Basil Launches Revamped Diamond Mattress Collection Page, Highlighting Performance, Craftsmanship, and Personalized Comfort
  • Sleep Basil Curates a Clearer Brooklyn Bedding Experience for Performance-Minded Denver Sleepers

According to Gartner1, "EASM is an emerging concept that is growing quickly in terms of awareness within the security vendor community but at a slower pace within end-user organizations...They help security professionals identify exposed vulnerabilities from known and unknown enterprise assets and prioritize the most critical issues to be tackled...EASM should be part of a broader vulnerability and threat management effort aimed at discovering and managing internal- and external-facing assets and their potential vulnerabilities."

Traditional third-party risk management solutions have focused exclusively on the vendors and the IT infrastructures that are directly connected to the enterprise. This approach ignores the true scale of the problem and represents only the tip of the iceberg. Third-party vendors have also adopted a distributed IT infrastructure, and have built their applications and services using their own vendors and third-parties. Those in turn build their solutions upon even more partners. This extensive ecosystem creates an external attack surface that is uniquely appealing to hackers to attack, and extremely complicated for enterprises to manage securely.

Hackers are finding it easier to takeover or exploit the vulnerabilities in the third-party assets within the enterprise's ecosystem in order to carry out attacks such as: malicious code injection (Magecart-style attacks), DNS hijacks, or abusing the branded assets of an enterprise. These breaches ultimately lead to data loss, brand reputation damage, and stolen customer data for the enterprise.

"Security teams often can't effectively defend against attacks stemming from third-parties because they lack visibility into the total inventory and volume of assets they are connected to," said Cyberpion CEO Nethanel Gelertner. "They are unaware of the exposure to these external vulnerabilities, and can't identify and mitigate against these risks. In addition, the growth of these interconnected assets continues to explode due to trends in cloud-first architectures and digital transformation initiatives, meaning that assessing and protecting the attack surface has become even more challenging over time."

More on Washingtoner
  • Spokane City Council Members Introduce "Immigration Enforcement Free Zones"
  • Spokane: Mayor Brown Calls on Congress to Extend Temporary Protected Status for Haitian Community Members
  • Nevada Man Launches Nationwide Animal Abuse Registry
  • New Threat Management Workshop Brings Hands-On BTAM Training to Spokane Valley
  • Star-powered Kappa Takeover Weekend Returns to the DMV June 18- 21, 2026, Hosted By Comedian Joe Clair W/ Dj Quick Silva (the Party Kingpin)

About Cyberpion

Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets that form an external attack surface. Knowing how your organization is vulnerable, where those threats come from, and what infrastructures are at risk, is critical to preventing an attack before it happens. Cyberpion helps organizations mitigate these advanced threats by continuously monitoring, discovering, and assessing the threat vectors present throughout online ecosystems that exist outside the traditional security perimeter. With an R&D team based in Israel, the company is funded by leading cybersecurity venture capitalists. To learn more, visit cyberpion.com.

For more information, please contact:
Josh Turner
Si14 Global Communications
josh.[email protected]

1 Gartner, "Emerging Technologies: Critical Insights for External Attack Surface Management" by Ruggero Contu, Elizabeth Kim and Mark Wah, March 19, 2021

SOURCE Cyberpion
Show All News | Report Violation

0 Comments
1000 characters max.

Latest on Washingtoner
  • InspireTech Global and SKADI Cyber Defense Announce Strategic Partnership to Deliver Autonomous Cybersecurity to Canadian Education and Public Sector
  • Kaltra Expands Microchannel Innovation to Deliver Lower Refrigerant Charge
  • Georgia's Lanier Islands Resort Tees Up for a New Era of Golf in Spring 2026
  • City of Tacoma Offers Virtual Workshop for Organizations New to Local Affordable Housing Development Funding Application Process
  • Eagle Americas Expands Into the Western U.S. With High West Machine Tool
  • Tacoma: Street Closures Projected to Start the Week of February 9 for Residential Street Restoration Program Maintenance Work
  • City of Tacoma Launches Regional Driver Safety Campaign to Support Safer Streets
  • Desert Mountain Club Earns Prestigious Blue Zones Approved™ Triple Designation, a New Standard for Well-Being in a Luxury Lifestyle Community
  • Outsports announces record-breaking number of LGBTQ+ athletes at 2026 Milan Winter Olympics
  • Sheffield Clinic Highlights Safe, Inclusive Laser Hair Removal While Improving Access
  • Appliance EMT Partners with Kids Motel Ministry in Metro Atlanta
  • CNCPW Divulga Dados de Liquidez do 1º Trimestre: Confirma 100% de Reservas e Atualiza Protocolos de "Saque CNCPW" Contra Fluxos Ilícitos
  • Tech Workers Are Escaping "Forever Layoffs" By Becoming Their Own Boss
  • Spokane: Phone Video Of Abduction/Assault Of Teen Leads To Multiple Arrests
  • Spokane Receives $200,000 Grant from U.S. Conference of Mayors to Support Youth Wellness Zone
  • Heritage at South Brunswick Celebrates First Home Closing and Strong Sales Momentum
  • Tacoma: 'Bonding Basics' Workshop on February 19
  • WinkBeds High-Performance Hybrid Mattresses Debut at Sleep Basil Denver With In-Store Comfort Testing
  • Tampa Nonprofit Expands Recovery Services for Men in Crisis With New Farm Program in Plant City
  • Applications for 2026-2027 Tacoma Creates Funding Now Available
_catLbl0 _catLbl1

Popular on Washingtoner

  • City of Tacoma Secures Over $4 Million in Transportation Improvement Board Grants - 163
  • TBM Council Appoints Four Distinguished Leaders to Board of Directors - 139
  • Spokane: Council to Hold Press Conference to Discuss Further Information on Department of Justice Grant
  • Spokane: Council Members Official Swearing In Ceremony
  • Spokane: Mayor Brown Appoints New Emergency Communications Director
  • TBM Council Appoints U.S. Department of Transportation CDIO Pavan Pidugu to Board of Directors
  • New Report Reveals Surprising Trends in Illinois Airport Accidents
  • New Analysis Reveals Most Patients Discontinue Weight Loss Drugs Within First Year
  • Urban Bush Women Celebrates Bessie Award Nominations & Winter 2026 Touring
  • Custom Home Builder Connecticut Valley Homes Wins 2025 Home of the Year from the Modular Home Builders Association

Similar on Washingtoner

  • Nest Finders Property Management Named #1 in Jacksonville and Ranked #99 Nationwide
  • Market Value Enhancement From 2 Important New US Patents Issued for Strengthening Hair Enzyme Booster Technology to Caring Brands (NAS DAQ: CABR)
  • Nevada Man Launches Nationwide Animal Abuse Registry
  • Scoop Social Co. Wins The Knot and WeddingWire Awards as Brand Expands Nationwide
  • Strategic Expansion with 3 New Alliances — Jefferson Beach Yacht Sales, CFR YS & flyExclusive Incentive Partnership: Off The Hook YS: (N Y S E: OTH)
  • Super League (N A S D A Q: SLE) Advances AI-Driven Playable Media with AdArcade, Solsten, and Meta-Stadiums Partnerships, Plus Roblox Theatre Launch
  • Good Vibes Club and Instant IP Forge Strategic Partnership to Secure IP Brand Value in a Booming Digital Economy
  • Inkdnylon Simplifies Digitizing and Vector Art Nationwide With Clear Pricing and Guided File Support
  • InspireTech Global and SKADI Cyber Defense Announce Strategic Partnership to Deliver Autonomous Cybersecurity to Canadian Education and Public Sector
  • Georgia's Lanier Islands Resort Tees Up for a New Era of Golf in Spring 2026
Copyright © 2026 washingtoner.com | Terms of Service | Privacy Policy | Contact Us | Contribute