Menu
Washingtoner
  • Home
  • Business
  • Construction
  • Crypto
  • Marketing
  • Home
  • Information Technology
  • Financial
  • Aerospace
Washingtoner

Cyberpion Reveals A Quarter of Fortune 500 Companies Have Exploitable Vulnerabilities in their External IT Network
Washingtoner/10132666

Trending...
  • Tacoma: At-Large City Council Member Olgy Diaz Hosts 'Bridging the Gap: Local Solutions in the Federal Landscape' on December 6
  • Signature Smiles Dental Group Unveils New User-Friendly Website
  • Spokane: New Ordinance Seeks to Prohibit Sale, Distribution of Kratom
KIRKLAND, Wash. and TEL AVIV, Israel, Sept. 14, 2021 /PRNewswire/ -- Cyberpion, a cybersecurity pioneer in external attack surface management (EASM), today presented research showing that nearly three quarters of Fortune 500 companies' IT infrastructure exists outside their organization, a quarter of which was found to have a known vulnerability that threat actors could infiltrate to access sensitive employee or customer data.

Key research findings:
  • 73% of Fortune 500 companies' total IT infrastructure is external to the organization, of which 24% is considered at risk or has a known vulnerability
    • The total IT infrastructure includes the IT assets that are owned and operated by vendors the Fortune 500 enterprises incorporated into their online footprint
    • These IT assets include servers, cloud storage, CDNs, DNS (Domain Name Servers), email servers and other online elements
  • 71% of total cloud-based IT assets are external to the organization, of which 25% failed at least one security test
    • An example of cloud vulnerability includes cloud storage configured to allow anyone to read or write its contents
  • On average, a Fortune 500 company's infrastructure contains 126 different login pages for either customer or employee portals or services - the highest number was over 3,000
    • Nearly 10% of these login pages are considered insecure due to the transmission of unencrypted login data, or issues with SSL certificates, which helps ensure that the submission is being sent to the authorized destination
    • 30% allow transmission over HTTP
    • 12% have invalid certificates/encryption
    • Hackers exploiting these logins could access a wealth of sensitive employee or customer data
  • Fortune 500 organizations connect to an average of 951 cloud assets, of which nearly 5% are vulnerable to severe abuse
    • For example, a misconfigured AWS bucket could allow hackers to read or overwrite the data which could be customer PII or application code
    • The largest exposure was well over 30K cloud assets

Cyberpion collected these results by performing a cursory single-pass scan of the public and internet-facing assets of every Fortune 500 company in the first half of 2021.

More on Washingtoner
  • Tacoma: FAQs on Proposed 0.1% Criminal Justice Sales & Use Tax
  • UK Financial Ltd Announces A Special Board Meeting Today At 4PM: Orders MCAT Lock on CATEX, Adopts ERC-3643 Standard, & Cancels $0.20 MCOIN for $1
  • Tacoma: City of Destiny Awards Nominations Accepted Now Through January 29, 2026
  • Spokane: National Pearl Harbor Remembrance Day
  • 6 Holiday Looks That Scream "Old Money" But Cost Less Than Your Christmas Tree

According to Gartner1, "EASM is an emerging concept that is growing quickly in terms of awareness within the security vendor community but at a slower pace within end-user organizations...They help security professionals identify exposed vulnerabilities from known and unknown enterprise assets and prioritize the most critical issues to be tackled...EASM should be part of a broader vulnerability and threat management effort aimed at discovering and managing internal- and external-facing assets and their potential vulnerabilities."

Traditional third-party risk management solutions have focused exclusively on the vendors and the IT infrastructures that are directly connected to the enterprise. This approach ignores the true scale of the problem and represents only the tip of the iceberg. Third-party vendors have also adopted a distributed IT infrastructure, and have built their applications and services using their own vendors and third-parties. Those in turn build their solutions upon even more partners. This extensive ecosystem creates an external attack surface that is uniquely appealing to hackers to attack, and extremely complicated for enterprises to manage securely.

Hackers are finding it easier to takeover or exploit the vulnerabilities in the third-party assets within the enterprise's ecosystem in order to carry out attacks such as: malicious code injection (Magecart-style attacks), DNS hijacks, or abusing the branded assets of an enterprise. These breaches ultimately lead to data loss, brand reputation damage, and stolen customer data for the enterprise.

"Security teams often can't effectively defend against attacks stemming from third-parties because they lack visibility into the total inventory and volume of assets they are connected to," said Cyberpion CEO Nethanel Gelertner. "They are unaware of the exposure to these external vulnerabilities, and can't identify and mitigate against these risks. In addition, the growth of these interconnected assets continues to explode due to trends in cloud-first architectures and digital transformation initiatives, meaning that assessing and protecting the attack surface has become even more challenging over time."

More on Washingtoner
  • FlintLab Announces Strategic Partnership with Genymotion
  • From Cheer to Courtroom: The Hidden Legal Risks in Your Holiday Eggnog
  • West Coast Hospitality Assumes Management of The Dundee Hotel
  • Spokane: Council Member Paul Dillon Honored with Legislative Champion Award by We Train Washington
  • Controversial Vegan Turns Rapper Launches First Song, "Psychopathic Tendencies."

About Cyberpion

Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets that form an external attack surface. Knowing how your organization is vulnerable, where those threats come from, and what infrastructures are at risk, is critical to preventing an attack before it happens. Cyberpion helps organizations mitigate these advanced threats by continuously monitoring, discovering, and assessing the threat vectors present throughout online ecosystems that exist outside the traditional security perimeter. With an R&D team based in Israel, the company is funded by leading cybersecurity venture capitalists. To learn more, visit cyberpion.com.

For more information, please contact:
Josh Turner
Si14 Global Communications
josh.[email protected]

1 Gartner, "Emerging Technologies: Critical Insights for External Attack Surface Management" by Ruggero Contu, Elizabeth Kim and Mark Wah, March 19, 2021

SOURCE Cyberpion
Filed Under: Business

Show All News | Report Violation

0 Comments
1000 characters max.

Latest on Washingtoner
  • Top10Christmas.co.uk Releases the UK Christmas Toy Trends 2025 Report
  • Talagat Business Academy Announces Joint Certificate Program With The University of Chicago Booth School of Business
  • LocaXion and Asseco CEIT Announce First-to-Market RTLS-Driven Digital Twin Platform for Healthcare, Manufacturing, and Logistics
  • Slotozilla Launches New Report on How AI Is Reshaping Careers and Society
  • Tacoma City Council Approves Tideflats Subarea Plan
  • OKAVA Pharmaceuticals Announces First Cat Dosed in MEOW-1 Study of OKV-119, the World's First Clinical-Stage GLP-1 Weight-Loss Therapy for Pets
  • Explosive Growth in U.S. Cryptocurrency Cloud Mining Sets The Stage for New Platform Launch with Daily Rewards in a Transparent Revenue-Share Model
  • Qtex Cierra Ronda de $7 Millones para Estandarizar la Banca Transfronteriza en los Mercados Emergentes de Latinoamérica
  • Boeing–Airbus Accreditation Breakdown: How "Probably" Certificates Created Worldwide Risk
  • Spokane: Suspect in Custody After Shooting Leaves One Subject Deceased
  • America's Most Festive Garages Wanted for Garage.com's 2025 Holiday Contest
  • Spokane: Funding Available for Culturally Specific Treatment of Opioid Use Disorder Grants
  • FDA Accepts ANDA for KETAFREE™ as Analyst Sets $34 Price Target for NRx Pharmaceuticals: (N A S D A Q : NRXP) NRx is Poised for a massive Breakthrough
  • BEC Technologies Expands MX-220 5G Industrial Router Series for Edge Connectivity
  • "Latino Leaders Speak: Personal Stories of Struggle and Triumph, Volume II" Documents the Truth About Latino Excellence and Impact on American Society
  • Broadway Smile Boutique Unveils Modern Website for Enhanced Patient Experience
  • Fenix Consulting Group Expands Orange County Office to Meet Growing Client Demand
  • Signature Smiles Dental Group Unveils New User-Friendly Website
  • CCHR: New Data Shows Millions of U.S. Children Caught in Escalating Psychiatric Polypharmacy
  • QwickContractReview.com Launches $19 Contract Review Service to Protect Consumers from Hidden Contract Risks
_catLbl0 _catLbl1

Popular on Washingtoner

  • Liquidity Aggregation: US-Registered JHKXWL Integrates AI Analytics for Brazilian and Global Institutional Traders - 613
  • Wohler announces three SRT monitoring enhancements for its iVAM2-MPEG monitor and the addition of front panel PID selection of A/V/subtitle streams
  • BumblebeeSmart Introduces Rounded Busy Board Set for Preschoolers
  • 5,000 Australians Call for Clarity: NaturismRE's Petition Reaches Major Milestone
  • Sweet Memories Vintage Tees Debuts Historic ORCA™ Beverage Nostalgic Soda Collection
  • Liftoff Enterprises Launches Liftoff Spotlight,™ A Nationally Broadcast Platform Turning Conversations Into Revenue
  • Curated Domain Name Marketplace
  • Cut Costs & Boost Profits with the First Major Upgrade in 30 YEARS Replacing Rotary Lasers and Historic Clear Tube Altimeter Bubbles
  • Turbo vs. Experts: Tracking OddsTrader's AI Performance at the NFL's Midpoint
  • 2026 Oscars Betting Odds: One Battle After Another Favored for Best Picture

Similar on Washingtoner

  • Verb™ Presents Features Vanguard Personalized Indexing: Utilizing Advanced Tax-Loss Harvesting Technology
  • Inside the Fight for Affordable Housing: Avery Headley Joins Terran Lamp for a Candid Bronx Leadership Conversation
  • Record Revenues, Debt-Free Momentum & Shareholder Dividend Ignite Investor Attention Ahead of 2026–2027 Growth Targets: IQSTEL (N A S D A Q: IQST)
  • BRAG Hosts Holiday Benefit — Awards 10 Student Scholarships & Honors Timberland with the Corporate Impact Award
  • $80M+ Backlog as Florida Statewide Contract, Federal Wins, and Strategic Alliance Fuel Next Phase of AI-Driven Cybersecurity Growth: Cycurion $CYCU
  • LocaXion and Asseco CEIT Announce First-to-Market RTLS-Driven Digital Twin Platform for Healthcare, Manufacturing, and Logistics
  • Slotozilla Launches New Report on How AI Is Reshaping Careers and Society
  • Explosive Growth in U.S. Cryptocurrency Cloud Mining Sets The Stage for New Platform Launch with Daily Rewards in a Transparent Revenue-Share Model
  • Qtex Cierra Ronda de $7 Millones para Estandarizar la Banca Transfronteriza en los Mercados Emergentes de Latinoamérica
  • "Latino Leaders Speak: Personal Stories of Struggle and Triumph, Volume II" Documents the Truth About Latino Excellence and Impact on American Society
Copyright © 2025 washingtoner.com | Terms of Service | Privacy Policy | Contact Us | Contribute