Menu
Washingtoner
  • Home
  • Health
  • Boeing
  • Technology
  • Aerospace
  • Daryl Guberman
  • Business
  • ANSI-ANAB
  • Software
Washingtoner

Cyberpion Reveals A Quarter of Fortune 500 Companies Have Exploitable Vulnerabilities in their External IT Network
Washingtoner/10132666

Trending...
  • Applicants Sought for the Tacoma Creates Advisory Board
  • KLEKT Announces Appointment of Jay Kimpton to Board of Directors
  • Tacoma: City Manager Hyun Kim to Present 'Roadmap to Recovery' on May 12
KIRKLAND, Wash. and TEL AVIV, Israel, Sept. 14, 2021 /PRNewswire/ -- Cyberpion, a cybersecurity pioneer in external attack surface management (EASM), today presented research showing that nearly three quarters of Fortune 500 companies' IT infrastructure exists outside their organization, a quarter of which was found to have a known vulnerability that threat actors could infiltrate to access sensitive employee or customer data.

Key research findings:
  • 73% of Fortune 500 companies' total IT infrastructure is external to the organization, of which 24% is considered at risk or has a known vulnerability
    • The total IT infrastructure includes the IT assets that are owned and operated by vendors the Fortune 500 enterprises incorporated into their online footprint
    • These IT assets include servers, cloud storage, CDNs, DNS (Domain Name Servers), email servers and other online elements
  • 71% of total cloud-based IT assets are external to the organization, of which 25% failed at least one security test
    • An example of cloud vulnerability includes cloud storage configured to allow anyone to read or write its contents
  • On average, a Fortune 500 company's infrastructure contains 126 different login pages for either customer or employee portals or services - the highest number was over 3,000
    • Nearly 10% of these login pages are considered insecure due to the transmission of unencrypted login data, or issues with SSL certificates, which helps ensure that the submission is being sent to the authorized destination
    • 30% allow transmission over HTTP
    • 12% have invalid certificates/encryption
    • Hackers exploiting these logins could access a wealth of sensitive employee or customer data
  • Fortune 500 organizations connect to an average of 951 cloud assets, of which nearly 5% are vulnerable to severe abuse
    • For example, a misconfigured AWS bucket could allow hackers to read or overwrite the data which could be customer PII or application code
    • The largest exposure was well over 30K cloud assets

Cyberpion collected these results by performing a cursory single-pass scan of the public and internet-facing assets of every Fortune 500 company in the first half of 2021.

More on Washingtoner
  • T. Jones Group's Cameron Jones Serves as Judge for the 2026 CHBA National Awards for Housing Excellence
  • The AI Direction Deficit: TripleTen Study Finds Staff Get Told to Use AI — But Not Trained to Use It
  • Spokane: Flags Lowered for Peace Officers Memorial Day
  • $29.8 Million Record Setting Q1 with Boosted Annual Guidance to $160 Million for Expanding Pre-Owned Boat Dealer: Off The Hook YS, Inc. N Y S E: OTH
  • All About Technology Celebrates 25 Years of Bridging Detroit's Digital Divide

According to Gartner1, "EASM is an emerging concept that is growing quickly in terms of awareness within the security vendor community but at a slower pace within end-user organizations...They help security professionals identify exposed vulnerabilities from known and unknown enterprise assets and prioritize the most critical issues to be tackled...EASM should be part of a broader vulnerability and threat management effort aimed at discovering and managing internal- and external-facing assets and their potential vulnerabilities."

Traditional third-party risk management solutions have focused exclusively on the vendors and the IT infrastructures that are directly connected to the enterprise. This approach ignores the true scale of the problem and represents only the tip of the iceberg. Third-party vendors have also adopted a distributed IT infrastructure, and have built their applications and services using their own vendors and third-parties. Those in turn build their solutions upon even more partners. This extensive ecosystem creates an external attack surface that is uniquely appealing to hackers to attack, and extremely complicated for enterprises to manage securely.

Hackers are finding it easier to takeover or exploit the vulnerabilities in the third-party assets within the enterprise's ecosystem in order to carry out attacks such as: malicious code injection (Magecart-style attacks), DNS hijacks, or abusing the branded assets of an enterprise. These breaches ultimately lead to data loss, brand reputation damage, and stolen customer data for the enterprise.

"Security teams often can't effectively defend against attacks stemming from third-parties because they lack visibility into the total inventory and volume of assets they are connected to," said Cyberpion CEO Nethanel Gelertner. "They are unaware of the exposure to these external vulnerabilities, and can't identify and mitigate against these risks. In addition, the growth of these interconnected assets continues to explode due to trends in cloud-first architectures and digital transformation initiatives, meaning that assessing and protecting the attack surface has become even more challenging over time."

More on Washingtoner
  • iatroX surpasses 500,000 clinical queries and expands specialist exam coverage
  • Inside-Out Hollywood: The Relentless Rise of Joseph Nybyk (AKA Joseph Neibich)
  • Lumetra Launches Engram, an MCP-Native Memory Layer Scoring 91.6% on LongMemEval
  • Spokane Parks & Recreation's Therapeutic Recreation Receives Donation
  • SRK Collective Media Group Launches with a Modern Approach to Media, Authority Building, and Cultural Visibility

About Cyberpion

Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets that form an external attack surface. Knowing how your organization is vulnerable, where those threats come from, and what infrastructures are at risk, is critical to preventing an attack before it happens. Cyberpion helps organizations mitigate these advanced threats by continuously monitoring, discovering, and assessing the threat vectors present throughout online ecosystems that exist outside the traditional security perimeter. With an R&D team based in Israel, the company is funded by leading cybersecurity venture capitalists. To learn more, visit cyberpion.com.

For more information, please contact:
Josh Turner
Si14 Global Communications
josh.[email protected]

1 Gartner, "Emerging Technologies: Critical Insights for External Attack Surface Management" by Ruggero Contu, Elizabeth Kim and Mark Wah, March 19, 2021

SOURCE Cyberpion
Show All News | Disclaimer | Report Violation

0 Comments
1000 characters max.

Latest on Washingtoner
  • Longevity Academy Launches The Longevity Leaders Project with Interview of Respira Global CEO
  • From Blank Page to Published Book
  • Virginia Marchese's Paradox: A Nation Still Deciding Who Belongs Examines Race, Migration, Law, and America's Unfinished Struggle for Equality
  • Larry R. Wasion's Jump Gate III RoadMaker Blends Cutting-Edge Sci-Fi with High-Stakes Space Exploration and Complex Technologies
  • American Mensa and Davidson Institute Join Forces To Strengthen Support for Profoundly Gifted Youth
  • SpeedyIndex Rolls Out Automated API for Mass URL Verification, Solving the Backlink Blind Spot for SEO Agencies
  • KLEKT Announces Appointment of Jay Kimpton to Board of Directors
  • Michigan Attorney General Closed FGM Licensing Investigations Months Before Federal Case Ended, Records Show
  • Mensa Foundation Event Reframes Brain Health for Every Age
  • DLT Resolution, Inc. (Stock Symbol: DLTI) Expands Into the $224 Billion Life Settlements Market While Accelerating Telecom Growth Across Canada
  • Ashley Wineland's 'Love + Heartbreak' Tour Brings her Emotional and Empowering Album 'Wineland' to Nationwide Audiences
  • Tacoma City Council Restricts Unauthorized Use of Public Property for Civil Immigration Enforcement
  • Spokane Police investigate shooting in north Spokane and make an arrest
  • People & Stories/Gente y Cuentos Welcomes Two New Trustees as Organization Enters 54th Year and Expands Community Reach
  • Tacoma: City Manager Hyun Kim Details 'Roadmap to Recovery' Addressing the City's General Fund Deficit and Modernizing City Operations
  • With a Dream and a Team, Monalisa Okojie Is Empowering the Next Generation Through EXPOSE NGO
  • Spokane: DUI Driver Taken Into Custody After Attempting to Flee from Officers
  • Tacoma Police Department to Recognize Five Tacoma Public School Employees Who Intervened in Violent Assault
  • American Properties Realty, Inc. Celebrates 2026 FAME Awards - Community of the Year - Heritage at South Brunswick
  • Spokane City Council Approves Activation of Public Spaces Program
_catLbl0 _catLbl1

Popular on Washingtoner

  • Altruvest and Financial Executives International Canada Announce Strategic Partnership to Strengthen Nonprofit Boards Across Canada
  • Virginia Moving Company Nearly Doubles Customer Calls in Two Weeks After Switching to CARL — the Bold New Alternative to WordPress
  • Freedomtech Solutions creates 'Global Data Centre Network (IDCN)'
  • New Report Reveals Plane Crashes Are Not Where You'd Think
  • Umbrella Becomes First FinOps Platform to Support AWS Billing Transfer Onboarding
  • L2 Aviation Acquires Advance Aero
  • Seattle Filmmaker Maikaru Launches Mainasty Press with Ambitious "21 Novels in 21 Months" Initiative
  • City Council Adopts Updated Resolution for ‘Connect Tacoma’ Ballot Proposition
  • Tacoma: Pothole Palooza Returns May 4 – 15 to Focus on Maintenance and Preservation of 10 Arterial Roadways
  • Axencis Launches Performance Partnership for Brand Protection

Similar on Washingtoner

  • Collectibles EvoRelic Celebrates Stellar 4.8-Star Customer Rating
  • T. Jones Group's Cameron Jones Serves as Judge for the 2026 CHBA National Awards for Housing Excellence
  • $29.8 Million Record Setting Q1 with Boosted Annual Guidance to $160 Million for Expanding Pre-Owned Boat Dealer: Off The Hook YS, Inc. N Y S E: OTH
  • All About Technology Celebrates 25 Years of Bridging Detroit's Digital Divide
  • MSBG Corporation Acquires GridWatch US Telemetry Automation System
  • T. Jones Group Named Finalist Across Multiple Categories at the 2026 Georgie Awards
  • The Simplest Small Business You're Probably Not Thinking About
  • EDC Weekend Comedy Special Featuring Don Barnhart & Friends — Use Promo Code FRIEND for 50% Off
  • N Y S E: OTH Off The Hook YS Is Building a Vertically Integrated Marine Empire — And Investors Are Starting to Notice
  • Concierge Title Agency Merges with Independence Title, Inc. to Deliver an Expanded Concierge Closing Experience Across South Florida
Copyright © 2026 washingtoner.com | Terms of Service | Privacy Policy | Contact Us | Contribute