Menu
Washingtoner
  • Home
  • Business
  • Aerospace
  • Construction
  • Transportation
  • Boeing
  • Manufacturing
  • Kelly Ortberg
  • Crypto
Washingtoner

Cyberpion Reveals A Quarter of Fortune 500 Companies Have Exploitable Vulnerabilities in their External IT Network
Washingtoner/10132666

Trending...
  • New Free Science Bingo Cards Help Grade 1 Students Learn Through Play
  • Spokane Police Chief's statement
  • Tacoma: Registration Now Open for OMWBE Active Certification Class on November 17
KIRKLAND, Wash. and TEL AVIV, Israel, Sept. 14, 2021 /PRNewswire/ -- Cyberpion, a cybersecurity pioneer in external attack surface management (EASM), today presented research showing that nearly three quarters of Fortune 500 companies' IT infrastructure exists outside their organization, a quarter of which was found to have a known vulnerability that threat actors could infiltrate to access sensitive employee or customer data.

Key research findings:
  • 73% of Fortune 500 companies' total IT infrastructure is external to the organization, of which 24% is considered at risk or has a known vulnerability
    • The total IT infrastructure includes the IT assets that are owned and operated by vendors the Fortune 500 enterprises incorporated into their online footprint
    • These IT assets include servers, cloud storage, CDNs, DNS (Domain Name Servers), email servers and other online elements
  • 71% of total cloud-based IT assets are external to the organization, of which 25% failed at least one security test
    • An example of cloud vulnerability includes cloud storage configured to allow anyone to read or write its contents
  • On average, a Fortune 500 company's infrastructure contains 126 different login pages for either customer or employee portals or services - the highest number was over 3,000
    • Nearly 10% of these login pages are considered insecure due to the transmission of unencrypted login data, or issues with SSL certificates, which helps ensure that the submission is being sent to the authorized destination
    • 30% allow transmission over HTTP
    • 12% have invalid certificates/encryption
    • Hackers exploiting these logins could access a wealth of sensitive employee or customer data
  • Fortune 500 organizations connect to an average of 951 cloud assets, of which nearly 5% are vulnerable to severe abuse
    • For example, a misconfigured AWS bucket could allow hackers to read or overwrite the data which could be customer PII or application code
    • The largest exposure was well over 30K cloud assets

Cyberpion collected these results by performing a cursory single-pass scan of the public and internet-facing assets of every Fortune 500 company in the first half of 2021.

More on Washingtoner
  • Spokane: Protecting Your Home From Title Theft
  • Single Mom Launches GoFundMe to Prevent Eviction and Repair Car Ahead of Harsh Winter
  • Kaplan Morrell Law Firm Represents Former NHL Player in Workers' Compensation Case Drawing National Attention
  • Local Lighting Experts Debut AI Christmas Decorator: Upload a Photo, Get Instant Professional Holiday Design-- Completely Free
  • Surf Air Mobility (N Y S E: SRFM) Accelerates Regional Air Mobility Revolution with Electra Aero Partnership, Palantir Alliance, and Record Revenue

According to Gartner1, "EASM is an emerging concept that is growing quickly in terms of awareness within the security vendor community but at a slower pace within end-user organizations...They help security professionals identify exposed vulnerabilities from known and unknown enterprise assets and prioritize the most critical issues to be tackled...EASM should be part of a broader vulnerability and threat management effort aimed at discovering and managing internal- and external-facing assets and their potential vulnerabilities."

Traditional third-party risk management solutions have focused exclusively on the vendors and the IT infrastructures that are directly connected to the enterprise. This approach ignores the true scale of the problem and represents only the tip of the iceberg. Third-party vendors have also adopted a distributed IT infrastructure, and have built their applications and services using their own vendors and third-parties. Those in turn build their solutions upon even more partners. This extensive ecosystem creates an external attack surface that is uniquely appealing to hackers to attack, and extremely complicated for enterprises to manage securely.

Hackers are finding it easier to takeover or exploit the vulnerabilities in the third-party assets within the enterprise's ecosystem in order to carry out attacks such as: malicious code injection (Magecart-style attacks), DNS hijacks, or abusing the branded assets of an enterprise. These breaches ultimately lead to data loss, brand reputation damage, and stolen customer data for the enterprise.

"Security teams often can't effectively defend against attacks stemming from third-parties because they lack visibility into the total inventory and volume of assets they are connected to," said Cyberpion CEO Nethanel Gelertner. "They are unaware of the exposure to these external vulnerabilities, and can't identify and mitigate against these risks. In addition, the growth of these interconnected assets continues to explode due to trends in cloud-first architectures and digital transformation initiatives, meaning that assessing and protecting the attack surface has become even more challenging over time."

More on Washingtoner
  • Cybersecurity is Fast Becoming a Vital Issue for Protecting Personal Information and Portfolio Wealth
  • 10 Essential Tips for Maximizing Value When Choosing Your Orlando Wedding Venue
  • Americans Are Trading Offices for Beaches: How Business Ownership Enables the Ultimate Location Freedom
  • Boston Industrial Solutions' Natron® DC Series Ink Has Had an Upgrade!
  • Colony Ridge Proudly Supports the All Ears! 2025 Sporting Clays Tournament

About Cyberpion

Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets that form an external attack surface. Knowing how your organization is vulnerable, where those threats come from, and what infrastructures are at risk, is critical to preventing an attack before it happens. Cyberpion helps organizations mitigate these advanced threats by continuously monitoring, discovering, and assessing the threat vectors present throughout online ecosystems that exist outside the traditional security perimeter. With an R&D team based in Israel, the company is funded by leading cybersecurity venture capitalists. To learn more, visit cyberpion.com.

For more information, please contact:
Josh Turner
Si14 Global Communications
josh.[email protected]

1 Gartner, "Emerging Technologies: Critical Insights for External Attack Surface Management" by Ruggero Contu, Elizabeth Kim and Mark Wah, March 19, 2021

SOURCE Cyberpion
Filed Under: Business

Show All News | Report Violation

0 Comments
1000 characters max.

Latest on Washingtoner
  • Spokane: Council Community Days in Honor of Veterans Day
  • World Record Established: Million-Dollar Bilibin Screen Sells at Shapiro Auctions
  • HiLine Homes Launches "Big Build Savings Event" with Up to $35,000 Off New Home Builds
  • Lawproactive Launches Next-Generation CRM, Marrying Data and Location with Geo-Optimized Funnels for Attorney Lead Generation
  • POWER SOLUTIONS N.V. Partners with ENERGY33 LLC to Deliver a 40.5 MW Temporary Power Project for ECUACORRIENTE S.A. in Ecuador
  • Tacoma: Planned System Outages in November 2025
  • Pioneering the Future of Human-Computer Interaction Through AI-Powered Neural Input Technology: Wearable Devices Ltd. (N A S D A Q: WLDS)
  • Epic Pictures Group Sets North American Release Date for the Action Thriller LOST HORIZON
  • HR Soul Consulting Recognized as a 2025 Inc. Power Partner Award Winner for the Fourth Consecutive Year
  • Eramls Investment Alliance under Nolan Mercer Launches InsightNova System for AI-Driven Investing
  • Pullman Good Food Co-op Announces Future Home in the Heart of Downtown Pullman
  • Atrish Investment Alliance Under Asher Mercer Expands Global Compliance Collaboration
  • Spokane: Hope Soccer and Parks and Rec Partner to Expand Youth Soccer Access
  • Tacoma: Portion of McMurray Hill Road NE to Close for Hazardous Tree Removal
  • Tacoma: Connect With Creativity at 'Arts at the Armory' on November 15 and 16
  • Spokane: City Details Veterans Day Schedule
  • Brazil 021 Chicago Launches New Website and Expands with No-Gi Classes for All Levels
  • American Star Guard Unveils a Powerful Rebrand and Expanded Security Services Throughout Nevada
  • PlaceBased Media Expands Point-of-Care Advertising Inventory Across U.S. Clinic Network
  • Flexible Plan Investments launches FlexDirex, a first-to-market suite of single-stock ETF strategies in the U.S
_catLbl0 _catLbl1

Popular on Washingtoner

  • New Article by Roy J. Meidinger – Examines Hidden Hidden Healthcare Kickbacks
  • New Article Reveals Common Pricing Pitfalls in Flooring Projects — And How to Avoid Them
  • Spokane: City Construction Projects Traffic Impacts Next Week
  • Jaipur's Savista Retreat announces $299 all-inclusive nightly rate for two for the 2026 season, including meals and city-center transfers
  • Cancer Survivor Roslyn Franken Marks 30-Year Milestone with Empowering Gift for Women Survivors
  • GlobalBoost Announces Listing on Biconomy Exchange Expanding Accessibility of Decentralized Payments
  • Applicants Sought for the Tacoma Community Redevelopment Authority Board
  • Some Music for Donald's Bad Day
  • ExtraCarry Now Supports Taurus GX2 13-Round Mags and 15-Round Magazines
  • Oom Yung Doe Hosts Children's Halloween Safety Seminar in Kirkland

Similar on Washingtoner

  • UK Financial Ltd Unveils The First ERC-3643 Security Token Born from a Meme: Introducing MayaCat Regulated Security Token (SMCAT) Successor to MayaCat
  • Surf Air Mobility (N Y S E: SRFM) Accelerates Regional Air Mobility Revolution with Electra Aero Partnership, Palantir Alliance, and Record Revenue
  • Cybersecurity is Fast Becoming a Vital Issue for Protecting Personal Information and Portfolio Wealth
  • Americans Are Trading Offices for Beaches: How Business Ownership Enables the Ultimate Location Freedom
  • Colony Ridge Proudly Supports the All Ears! 2025 Sporting Clays Tournament
  • Powering the Next Frontier of the $1 Trillion Space Economy: Ascent Solar Technologies (N A S D A Q: ASTI)
  • Flick Truck Accident Law Joins the Commercial Vehicle Safety Alliance to Strengthen Truck Safety Advocacy
  • Passion Struck Network Debuts: A Creator-First Platform for Purpose-Driven Podcasting and Human Impact
  • Jonathan Malveaux Named Newest Member of Forbes Business Council
  • Sweet Beginnings: Sugar Queen Dessert Shop Opens in the Colony Ridge Community
Copyright © 2025 washingtoner.com | Terms of Service | Privacy Policy | Contact Us | Contribute