Menu
Washingtoner
  • Home
  • Health
  • Artificial Intelligence
  • Technology
  • Real Estate
  • Entertainment
  • Software
  • Information Technology
  • Business
Washingtoner

Cyberpion Reveals A Quarter of Fortune 500 Companies Have Exploitable Vulnerabilities in their External IT Network
Washingtoner/10132666

Trending...
  • Most Utah Deaths Never Reach the Medical Examiner. Postmortem Pathology Offers Salt Lake City a Private Autopsy Option
  • Tacoma: Officer Involved Shooting – 700 Block of South Stevens Street
  • CinderLabs Launches AI Agent Marketplace: Nine Pre-Built Agents for Regulated Industries
KIRKLAND, Wash. and TEL AVIV, Israel, Sept. 14, 2021 /PRNewswire/ -- Cyberpion, a cybersecurity pioneer in external attack surface management (EASM), today presented research showing that nearly three quarters of Fortune 500 companies' IT infrastructure exists outside their organization, a quarter of which was found to have a known vulnerability that threat actors could infiltrate to access sensitive employee or customer data.

Key research findings:
  • 73% of Fortune 500 companies' total IT infrastructure is external to the organization, of which 24% is considered at risk or has a known vulnerability
    • The total IT infrastructure includes the IT assets that are owned and operated by vendors the Fortune 500 enterprises incorporated into their online footprint
    • These IT assets include servers, cloud storage, CDNs, DNS (Domain Name Servers), email servers and other online elements
  • 71% of total cloud-based IT assets are external to the organization, of which 25% failed at least one security test
    • An example of cloud vulnerability includes cloud storage configured to allow anyone to read or write its contents
  • On average, a Fortune 500 company's infrastructure contains 126 different login pages for either customer or employee portals or services - the highest number was over 3,000
    • Nearly 10% of these login pages are considered insecure due to the transmission of unencrypted login data, or issues with SSL certificates, which helps ensure that the submission is being sent to the authorized destination
    • 30% allow transmission over HTTP
    • 12% have invalid certificates/encryption
    • Hackers exploiting these logins could access a wealth of sensitive employee or customer data
  • Fortune 500 organizations connect to an average of 951 cloud assets, of which nearly 5% are vulnerable to severe abuse
    • For example, a misconfigured AWS bucket could allow hackers to read or overwrite the data which could be customer PII or application code
    • The largest exposure was well over 30K cloud assets

Cyberpion collected these results by performing a cursory single-pass scan of the public and internet-facing assets of every Fortune 500 company in the first half of 2021.

More on Washingtoner
  • Spokane: U.S. Conference of Mayors, American Beverage Foundation Visit Youth Wellness Zone
  • Spokane: Disabled Smoke Alarm Contributes to Fatal Tiki Lodge Fire
  • Spokane Police Investigate Fatal Fire With Fire Department
  • Spokane: SPD and SFD Respond to Early Morning Fire in Downtown Apartments
  • City To Simplify Services by Routing Non-Emergency Police, Fire Calls through Spokane 311

According to Gartner1, "EASM is an emerging concept that is growing quickly in terms of awareness within the security vendor community but at a slower pace within end-user organizations...They help security professionals identify exposed vulnerabilities from known and unknown enterprise assets and prioritize the most critical issues to be tackled...EASM should be part of a broader vulnerability and threat management effort aimed at discovering and managing internal- and external-facing assets and their potential vulnerabilities."

Traditional third-party risk management solutions have focused exclusively on the vendors and the IT infrastructures that are directly connected to the enterprise. This approach ignores the true scale of the problem and represents only the tip of the iceberg. Third-party vendors have also adopted a distributed IT infrastructure, and have built their applications and services using their own vendors and third-parties. Those in turn build their solutions upon even more partners. This extensive ecosystem creates an external attack surface that is uniquely appealing to hackers to attack, and extremely complicated for enterprises to manage securely.

Hackers are finding it easier to takeover or exploit the vulnerabilities in the third-party assets within the enterprise's ecosystem in order to carry out attacks such as: malicious code injection (Magecart-style attacks), DNS hijacks, or abusing the branded assets of an enterprise. These breaches ultimately lead to data loss, brand reputation damage, and stolen customer data for the enterprise.

"Security teams often can't effectively defend against attacks stemming from third-parties because they lack visibility into the total inventory and volume of assets they are connected to," said Cyberpion CEO Nethanel Gelertner. "They are unaware of the exposure to these external vulnerabilities, and can't identify and mitigate against these risks. In addition, the growth of these interconnected assets continues to explode due to trends in cloud-first architectures and digital transformation initiatives, meaning that assessing and protecting the attack surface has become even more challenging over time."

More on Washingtoner
  • ResC4EU Final Event at KOMPOZYT-EXPO 2026 – Building Resilient European Supply Chains
  • Tacoma: Update Fourth Homicide Arrest – 2100 block of N 30th St
  • City of Tacoma Invites Community Members to Share Their Experience Crossing I-5
  • Statement from Tacoma Chief of Police Patti Jackson on Understanding the Office of Independent Investigations (OII)
  • Tacoma: 2026 AMOCAT Arts Award Winners Announced

About Cyberpion

Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets that form an external attack surface. Knowing how your organization is vulnerable, where those threats come from, and what infrastructures are at risk, is critical to preventing an attack before it happens. Cyberpion helps organizations mitigate these advanced threats by continuously monitoring, discovering, and assessing the threat vectors present throughout online ecosystems that exist outside the traditional security perimeter. With an R&D team based in Israel, the company is funded by leading cybersecurity venture capitalists. To learn more, visit cyberpion.com.

For more information, please contact:
Josh Turner
Si14 Global Communications
josh.[email protected]

1 Gartner, "Emerging Technologies: Critical Insights for External Attack Surface Management" by Ruggero Contu, Elizabeth Kim and Mark Wah, March 19, 2021

SOURCE Cyberpion
Show All News | Disclaimer | Report Violation

0 Comments
1000 characters max.

Latest on Washingtoner
  • "JACKIE the STRIPPER," Starring Charlotte Kirk and The PUSSYCAT DOLLS' Kimberly Wyatt, Now Streaming on PRIME
  • Migguel Anggelo Celebrates the Immigrant Experience, Latino Identity, and the Power of Iconic Latin Rhythms During Hispanic Heritage Month
  • Indianapolis Criminal Defense Firm Rigney Law LLC Relaunches Criminal Law Podcast "Tales from the Brown Desk"
  • 3ptechies Makes Its Articles Audio-Ready With Instaread Voice Technology
  • Genuine Hospitality, LLC Selected to Operate Fairfield Inn & Suites Tampa Wesley Chapel
  • Pregis to Highlight EPR Expertise, Sustainable Packaging Solutions and Live Automation Demonstrations at Pack Expo International 2026
  • Infinity Infusion Solutions Launches "Women Leading Infusion Care" Campaign for National Women in Business Month
  • HuskyTail Digital Puts AI to Work Behind the Scenes to Cut Client Turnaround Time
  • AI, Real-World Data "RWD" and U.S. Expansion Put Predictive Healthcare in Focus for POMDOCTOR Ltd. (N A S D A Q: POM)
  • $11.18 Million DARPA Award Ignites a Major New Catalyst as FDA, Robotic TMS and Commercialization Milestones Converge for NRx Pharmaceuticals, Inc
  • Kirk Shaw Veteran Producer Tells Intelligence Daily: "The Next Decade Will Belong to the Creator"
  • P-Wave Classics to publish Thomas Holcroft's The Adventures of Hugh Trevor in three volumes, beginning 19 January
  • Ad Leverage Sponsors ServiceTitan Pantheon 2026, Supporting Education and Growth in the Home Services Industry
  • DBF Viewer 2000 v9.32 Adds New Control for Data Export
  • Badanamu Partners With Moonbug Entertainment In Landmark Distribution Deal
  • Nutriband (N A S D A Q: NTRB): Fighting Back Against the Fentanyl Crisis With a New Approach to Safer Transdermal Medicines
  • Top 10 AI Trading Agents Beat Market at 91% Return for Hedge Funds (PANW, AAPL, IREN, JOBY, LUNR)
  • Oral statement on the situation of Chairman Lee Man-hee in pretrial detention in the Republic of Korea
  • A Sky Lites Drone Show welcomes new students University of Oregon
  • CinderLabs AIRA Governs NVIDIA's Open Agent Safety Platform, Turning Enforcement Into Evidence
_catLbl0 _catLbl1

Popular on Washingtoner

  • Spokane: Police Arrest Registered Sex Offender for Child Sexual Abuse Material - 142
  • Continuous You Foundation Announces Partnership with Haawke Neural Technology - 107
  • Future Intelligence Think Tank Surpasses 1,000 Members Exploring Human and Artificial Intelligence
  • Tacoma: Applicants Sought for the Board of Ethics
  • Tacoma: Applicants Sought for the Audit Advisory Board
  • Applicants Sought for the Tacoma Arts Commission and the Tacoma Creates Advisory Board
  • Cruxy shortlisted for two Private Equity Wire® US Awards 2026: Advisory Firm of the Year (Overall) & Value Creation Consulting Firm of the Year
  • Lake Norman Philharmonic - Free Community Concert
  • OneVizion Launches Vera AI, Bringing Connected Operational Context to Infrastructure Teams
  • City of Spokane to Install First 'Emergency Streets' Lane Closure After Weekend Fatal Crash

Similar on Washingtoner

  • ResC4EU Final Event at KOMPOZYT-EXPO 2026 – Building Resilient European Supply Chains
  • NIL Club Data Shows Brands Are Looking Beyond Follower Counts in College Sports
  • NYC Banners Delivers High-Stakes UN General Assembly Backdrop for the US Department of State Event
  • Genuine Hospitality, LLC Selected to Operate Fairfield Inn & Suites Tampa Wesley Chapel
  • Pregis to Highlight EPR Expertise, Sustainable Packaging Solutions and Live Automation Demonstrations at Pack Expo International 2026
  • Infinity Infusion Solutions Launches "Women Leading Infusion Care" Campaign for National Women in Business Month
  • HuskyTail Digital Puts AI to Work Behind the Scenes to Cut Client Turnaround Time
  • AI, Real-World Data "RWD" and U.S. Expansion Put Predictive Healthcare in Focus for POMDOCTOR Ltd. (N A S D A Q: POM)
  • $11.18 Million DARPA Award Ignites a Major New Catalyst as FDA, Robotic TMS and Commercialization Milestones Converge for NRx Pharmaceuticals, Inc
  • Nutriband (N A S D A Q: NTRB): Fighting Back Against the Fentanyl Crisis With a New Approach to Safer Transdermal Medicines
Copyright © 2026 washingtoner.com | Terms of Service | Privacy Policy | Contact Us | Contribute