Menu
Washingtoner
  • Home
  • Boeing
  • Health
  • Aerospace
  • Daryl Guberman
  • Technology
  • Business
  • ANSI-ANAB
  • Non-profit
Washingtoner

Cyberpion Reveals A Quarter of Fortune 500 Companies Have Exploitable Vulnerabilities in their External IT Network
Washingtoner/10132666

Trending...
  • New plusOne Research Finds the Orgasm Gap Is a 30-Point Chasm — and Confirms It Isn't Biology
  • Five-star Review for Berklee School of Music Textbook
  • Melospeech Inc. Awarded New NYSDOH BEI Contract in New York
KIRKLAND, Wash. and TEL AVIV, Israel, Sept. 14, 2021 /PRNewswire/ -- Cyberpion, a cybersecurity pioneer in external attack surface management (EASM), today presented research showing that nearly three quarters of Fortune 500 companies' IT infrastructure exists outside their organization, a quarter of which was found to have a known vulnerability that threat actors could infiltrate to access sensitive employee or customer data.

Key research findings:
  • 73% of Fortune 500 companies' total IT infrastructure is external to the organization, of which 24% is considered at risk or has a known vulnerability
    • The total IT infrastructure includes the IT assets that are owned and operated by vendors the Fortune 500 enterprises incorporated into their online footprint
    • These IT assets include servers, cloud storage, CDNs, DNS (Domain Name Servers), email servers and other online elements
  • 71% of total cloud-based IT assets are external to the organization, of which 25% failed at least one security test
    • An example of cloud vulnerability includes cloud storage configured to allow anyone to read or write its contents
  • On average, a Fortune 500 company's infrastructure contains 126 different login pages for either customer or employee portals or services - the highest number was over 3,000
    • Nearly 10% of these login pages are considered insecure due to the transmission of unencrypted login data, or issues with SSL certificates, which helps ensure that the submission is being sent to the authorized destination
    • 30% allow transmission over HTTP
    • 12% have invalid certificates/encryption
    • Hackers exploiting these logins could access a wealth of sensitive employee or customer data
  • Fortune 500 organizations connect to an average of 951 cloud assets, of which nearly 5% are vulnerable to severe abuse
    • For example, a misconfigured AWS bucket could allow hackers to read or overwrite the data which could be customer PII or application code
    • The largest exposure was well over 30K cloud assets

Cyberpion collected these results by performing a cursory single-pass scan of the public and internet-facing assets of every Fortune 500 company in the first half of 2021.

More on Washingtoner
  • Scott Ritsema of Bisnar Chase Selected for 2026 National Traumatic Brain Injury Association
  • Flint Youth Film Festival Shifts Gears, Becomes Vehicle City Film Festival
  • Celebrate Tacoma's Top Volunteers and Service Providers at the 2026 City of Destiny Awards
  • 62% of Gen X have no estate planning documents — Trust & Will research identifies "the Sandwich Gap"
  • Nayarit's Jungle Coast Redefines Luxury Travel on Mexico's Pacific Now More Accessible Than Ever

According to Gartner1, "EASM is an emerging concept that is growing quickly in terms of awareness within the security vendor community but at a slower pace within end-user organizations...They help security professionals identify exposed vulnerabilities from known and unknown enterprise assets and prioritize the most critical issues to be tackled...EASM should be part of a broader vulnerability and threat management effort aimed at discovering and managing internal- and external-facing assets and their potential vulnerabilities."

Traditional third-party risk management solutions have focused exclusively on the vendors and the IT infrastructures that are directly connected to the enterprise. This approach ignores the true scale of the problem and represents only the tip of the iceberg. Third-party vendors have also adopted a distributed IT infrastructure, and have built their applications and services using their own vendors and third-parties. Those in turn build their solutions upon even more partners. This extensive ecosystem creates an external attack surface that is uniquely appealing to hackers to attack, and extremely complicated for enterprises to manage securely.

Hackers are finding it easier to takeover or exploit the vulnerabilities in the third-party assets within the enterprise's ecosystem in order to carry out attacks such as: malicious code injection (Magecart-style attacks), DNS hijacks, or abusing the branded assets of an enterprise. These breaches ultimately lead to data loss, brand reputation damage, and stolen customer data for the enterprise.

"Security teams often can't effectively defend against attacks stemming from third-parties because they lack visibility into the total inventory and volume of assets they are connected to," said Cyberpion CEO Nethanel Gelertner. "They are unaware of the exposure to these external vulnerabilities, and can't identify and mitigate against these risks. In addition, the growth of these interconnected assets continues to explode due to trends in cloud-first architectures and digital transformation initiatives, meaning that assessing and protecting the attack surface has become even more challenging over time."

More on Washingtoner
  • $10 Million Annual Revenue Merger, Profitable Partner in AI Powered Specialty Automotive Sales Projected to Scale Above $200M: Stock Symbol: NWPG
  • Virginia Moving Company Nearly Doubles Customer Calls in Two Weeks After Switching to CARL — the Bold New Alternative to WordPress
  • RAS AP Consulting Launches Vendor Master File & Payment Controls Assessment for NACHA Phase 2 Compliance
  • Spokane: 2026 Wildfire & Forestry Safety Fair
  • Spokane AI Expert Adam Chronister to Discuss Authority Engineering at AI Roundtable Event

About Cyberpion

Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets that form an external attack surface. Knowing how your organization is vulnerable, where those threats come from, and what infrastructures are at risk, is critical to preventing an attack before it happens. Cyberpion helps organizations mitigate these advanced threats by continuously monitoring, discovering, and assessing the threat vectors present throughout online ecosystems that exist outside the traditional security perimeter. With an R&D team based in Israel, the company is funded by leading cybersecurity venture capitalists. To learn more, visit cyberpion.com.

For more information, please contact:
Josh Turner
Si14 Global Communications
josh.[email protected]

1 Gartner, "Emerging Technologies: Critical Insights for External Attack Surface Management" by Ruggero Contu, Elizabeth Kim and Mark Wah, March 19, 2021

SOURCE Cyberpion
Show All News | Disclaimer | Report Violation

0 Comments
1000 characters max.

Latest on Washingtoner
  • Statement from District 4 Council Member Sandesh Sadalge on Home in Tacoma Year One
  • 'Home in Tacoma' Sparks 62% Increase in Number of Proposed Housing Units in First Year
  • Food Journal Magazine Unveils Its Latest 'Best of Los Angeles' Culinary Discoveries
  • Boston Industrial Solutions Launches Natron® 717S Series: A New Flexible UV LED Ink for Ricoh GH2220 Printheads
  • 5 Things NYC Courier Services Won't Tell You About How Same-Day Delivery Actually Works
  • Spokane City Council Votes in Support of Moving Forward the STA Ballot Initiative
  • Tropidelic Links Up With International Reggae Star Collie Buddz and Eli Mac for Feel-Good Breakthrough Single "Follow Your Nature"
  • Save 15 Percent on Florida Keys Accommodations with KeysCaribbean's 'Advance Purchase Rate Discount'
  • Atelier 411 Studios and Columbus Fashion Council Present Red Carpet Experience at Gateway Film Center for The Devil Wears Prada 2
  • Hazel E Celebrates Birthday with Luxury "Goddess" Yacht Experience in Marina del Rey
  • Joseph Neibich sits down with Bold Jounrey (aka Joseph Nybyk)
  • AI Suite 360 Launches Done-For-You AI Implementation to Rescue SMBs from the "Frankenstein Tax"
  • Spokane: Mayor Brown Reestablishes City Arts Office, Names New Manager to Lead Effort
  • CX Network Releases Report on the Best AI Support Tools for SaaS Companies 2026
  • Outlier Pest Season Hits Willamette Valley as Mild Winter Drives Early Surge in Ant and Rodent Activity
  • Lokal Media House Wins Web Excellence Award for Black Plumbing Redesign
  • Lick Expands Flavored Massage Oil Collection with 10 New Indulgent Cream-Inspired Scents
  • New Research Identifies "Vacation Compatibility Gap" as the Hidden Force Shrinking How Long and With Whom Americans Travel
  • Melospeech Inc. Awarded New NYSDOH BEI Contract in New York
  • Five-star Review for Berklee School of Music Textbook
_catLbl0 _catLbl1

Popular on Washingtoner

  • Mensa Brings National Board Game Competition to Northern Virginia April 16-19 - 102
  • Tacoma: Lincoln Avenue Bridge to Close Saturday, April 18 for Asphalt Repairs
  • City Council to Discuss ‘Connect Tacoma’ Transportation Levy Replacement at April 14 Study Session
  • Attorney Joseph C. Kreps Files Lawsuit to Stop Alabama State Board of Pharmacy's Unlawful "Revenue-First" Rulemaking
  • Acuvance Appoints Sandeep Sabharwal to Board of Directors, Strengthening Leadership to Support Continued Platform Growth
  • Permian Museum Adds Photos of Fossils Discovered on a Meteorite
  • Su Che Publishing Announces New Children's Book Celebrating Vaisakhi Festival
  • Tacoma Police Department’s CALEA Public Comment Portal
  • Cinder Labs Launches AIRA Shield: Purpose-Built AI Security Platform to Combat Shadow AI
  • Game Day Private Jets Launches REVUP Platform to Transform Fan & Donor Travel Into a Revenue Engine for College Athletics

Similar on Washingtoner

  • $10 Million Annual Revenue Merger, Profitable Partner in AI Powered Specialty Automotive Sales Projected to Scale Above $200M: Stock Symbol: NWPG
  • Virginia Moving Company Nearly Doubles Customer Calls in Two Weeks After Switching to CARL — the Bold New Alternative to WordPress
  • RAS AP Consulting Launches Vendor Master File & Payment Controls Assessment for NACHA Phase 2 Compliance
  • Olga Torres Earns Repeat Recognition as a Top 2026 CFIUS Advisor
  • Strategic Talent Associates Launches THE ALIGNED RESET™
  • Calvetta Phair Founder & CEO Earns AOPA Foundation Flight Training Scholarship, Inspiring a New Generation of STEM Dreamers in Underserved Communities
  • 5 Things NYC Courier Services Won't Tell You About How Same-Day Delivery Actually Works
  • AI Suite 360 Launches Done-For-You AI Implementation to Rescue SMBs from the "Frankenstein Tax"
  • CX Network Releases Report on the Best AI Support Tools for SaaS Companies 2026
  • Five-star Review for Berklee School of Music Textbook
Copyright © 2026 washingtoner.com | Terms of Service | Privacy Policy | Contact Us | Contribute