Menu
Washingtoner
  • Home
  • Technology
  • Financial
  • Boeing
  • Aerospace
  • Daryl Guberman
  • Services
  • Non-profit
  • Business
Washingtoner

Cyberpion Reveals A Quarter of Fortune 500 Companies Have Exploitable Vulnerabilities in their External IT Network
Washingtoner/10132666

Trending...
  • Monexplora Explains the Options Mechanics Behind March's Tech Selloff and VIX Surge
  • NYC Composer/Educator Launches Debut Children's Book to Fantastic Reviews
  • Colony Ridge Communities Celebrates Successful Soccer Season Kickoff with Families and Youth
KIRKLAND, Wash. and TEL AVIV, Israel, Sept. 14, 2021 /PRNewswire/ -- Cyberpion, a cybersecurity pioneer in external attack surface management (EASM), today presented research showing that nearly three quarters of Fortune 500 companies' IT infrastructure exists outside their organization, a quarter of which was found to have a known vulnerability that threat actors could infiltrate to access sensitive employee or customer data.

Key research findings:
  • 73% of Fortune 500 companies' total IT infrastructure is external to the organization, of which 24% is considered at risk or has a known vulnerability
    • The total IT infrastructure includes the IT assets that are owned and operated by vendors the Fortune 500 enterprises incorporated into their online footprint
    • These IT assets include servers, cloud storage, CDNs, DNS (Domain Name Servers), email servers and other online elements
  • 71% of total cloud-based IT assets are external to the organization, of which 25% failed at least one security test
    • An example of cloud vulnerability includes cloud storage configured to allow anyone to read or write its contents
  • On average, a Fortune 500 company's infrastructure contains 126 different login pages for either customer or employee portals or services - the highest number was over 3,000
    • Nearly 10% of these login pages are considered insecure due to the transmission of unencrypted login data, or issues with SSL certificates, which helps ensure that the submission is being sent to the authorized destination
    • 30% allow transmission over HTTP
    • 12% have invalid certificates/encryption
    • Hackers exploiting these logins could access a wealth of sensitive employee or customer data
  • Fortune 500 organizations connect to an average of 951 cloud assets, of which nearly 5% are vulnerable to severe abuse
    • For example, a misconfigured AWS bucket could allow hackers to read or overwrite the data which could be customer PII or application code
    • The largest exposure was well over 30K cloud assets

Cyberpion collected these results by performing a cursory single-pass scan of the public and internet-facing assets of every Fortune 500 company in the first half of 2021.

More on Washingtoner
  • Middle World Herbs Expands Botanical Skincare with a Unique Herbal Deodorant
  • PandaGuarantee Launches Rent Guarantor Service in New York City
  • The $112M Marketing Lesson Joe Whyte Learned: Why 'More Traffic' Is the Biggest Lie in Digital Marketing
  • Daniel Kaufman Expands Kaufman & Company Real Estate Platform With New Acquisitions, AI-Driven Industrial Development and Nationwide Growth Initiative
  • Tacoma City Council Member Kristina Walker to Share Sound Transit Updates During March 31 Study Session

According to Gartner1, "EASM is an emerging concept that is growing quickly in terms of awareness within the security vendor community but at a slower pace within end-user organizations...They help security professionals identify exposed vulnerabilities from known and unknown enterprise assets and prioritize the most critical issues to be tackled...EASM should be part of a broader vulnerability and threat management effort aimed at discovering and managing internal- and external-facing assets and their potential vulnerabilities."

Traditional third-party risk management solutions have focused exclusively on the vendors and the IT infrastructures that are directly connected to the enterprise. This approach ignores the true scale of the problem and represents only the tip of the iceberg. Third-party vendors have also adopted a distributed IT infrastructure, and have built their applications and services using their own vendors and third-parties. Those in turn build their solutions upon even more partners. This extensive ecosystem creates an external attack surface that is uniquely appealing to hackers to attack, and extremely complicated for enterprises to manage securely.

Hackers are finding it easier to takeover or exploit the vulnerabilities in the third-party assets within the enterprise's ecosystem in order to carry out attacks such as: malicious code injection (Magecart-style attacks), DNS hijacks, or abusing the branded assets of an enterprise. These breaches ultimately lead to data loss, brand reputation damage, and stolen customer data for the enterprise.

"Security teams often can't effectively defend against attacks stemming from third-parties because they lack visibility into the total inventory and volume of assets they are connected to," said Cyberpion CEO Nethanel Gelertner. "They are unaware of the exposure to these external vulnerabilities, and can't identify and mitigate against these risks. In addition, the growth of these interconnected assets continues to explode due to trends in cloud-first architectures and digital transformation initiatives, meaning that assessing and protecting the attack surface has become even more challenging over time."

More on Washingtoner
  • Peony Massage Spa Kirkland Offers 50% Off First Visit – Licensed ABMP Member Serving Kirkland, Redmond & Bellevue
  • purelyIV Launches Lab Testing Services in Metro Detroit
  • Spokane Police Arrest Two At Saturday's Protest
  • On the 296th Anniversary of the Ceremony That Made His Ancestor Emperor, a Cherokee Descendant Publishes the Novel That Restores Him
  • NRx Pharmaceuticals Could Be on the Verge of a Breakout Year as AI, FDA Catalysts, and Mental Health Demand Converge

About Cyberpion

Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets that form an external attack surface. Knowing how your organization is vulnerable, where those threats come from, and what infrastructures are at risk, is critical to preventing an attack before it happens. Cyberpion helps organizations mitigate these advanced threats by continuously monitoring, discovering, and assessing the threat vectors present throughout online ecosystems that exist outside the traditional security perimeter. With an R&D team based in Israel, the company is funded by leading cybersecurity venture capitalists. To learn more, visit cyberpion.com.

For more information, please contact:
Josh Turner
Si14 Global Communications
josh.[email protected]

1 Gartner, "Emerging Technologies: Critical Insights for External Attack Surface Management" by Ruggero Contu, Elizabeth Kim and Mark Wah, March 19, 2021

SOURCE Cyberpion
Show All News | Report Violation

0 Comments
1000 characters max.

Latest on Washingtoner
  • Dr. Nadene Rose Shares the Secret to True Success: Faith, Obedience, and Divine Purpose
  • Spokane: Armed Barricaded Subject Causes N. Market St To Close
  • Enleaf Founder Joins AI Panel at Møde Campus to Help Spokane-Area Businesses Navigate the AI Shift
  • Tacoma: Lincoln Avenue Bridge to Close April 4 for Major Asphalt Repairs
  • Understanding Unexpected Death: Why Independent Autopsies Matter in Cases Without Clear Cause
  • Epic Pictures Group Sets North American Release Date for the Thriller NO ORDINARY HEIST
  • Award-Winning REALTOR® Paige Coker Joins Corcoran DeRonja Real Estate
  • Over 98% of crypto owners globally don't declare taxes, new report find
  • TicTac Group acquires French EdTech company Distrisoft
  • Suspect Arrested in February Shooting in South Tacoma
  • Tacoma: City's Events and Recognitions Committee Announces the City of Destiny Award Winners
  • Mark Dobosz Makes Donorassess.org Free To Every Nonprofit On The Planet
  • Genpak Announces Closure of Utah Manufacturing Facility
  • Systemic Certification Breakdown: Federal Oversight Undermined by ANAB Governance Conflicts (2018–2026)
  • Newborn Care Network Introduces Clinical Standard to Bridge the Six-Week Postpartum Gap
  • The AAA Metamorphosis: How Global Gaming Is Redefining Production Standards
  • Monexplora Explains the Options Mechanics Behind March's Tech Selloff and VIX Surge
  • Spokane: Shooting on Wellesley Leaves One Person Deceased and Another Injured
  • Spokane: District 3 Council Members to Host Community Town Hall
  • Spokane: City Recognizes Local Businesses for Excellent Wastewater Management
_catLbl0 _catLbl1

Popular on Washingtoner

  • Spokane: Indian Canyon Golf Course Opens Thursday, March 12, 2026
  • Independent Financial Agencies Upgrade City of Tacoma’s Bond Ratings Amid Broader Economic Uncertainty
  • Spokane: City Council Adopts "Immigration Enforcement Free Zones" Ordinance
  • City of Spokane Launches Residential Light Program
  • Spokane: Funding Available for Tourism and Cultural Investment Grant
  • New Book Warring From the Standpoint of the Throne Room Calls Believers to Pray From Victory
  • Pregis Expands Wind Energy Use, Advancing Progress Toward Net Zero by 2040
  • $167 Billion Pharma R&D Market Largely Untapped by AI Creates Major Growth Runway for KALA Bios Data-Sovereign AI Strategy: N A S D A Q: KALA
  • Summit Appoints Javier Cabeza as Data, AI, and Analytics Practice Lead
  • ANAB's Fraud Taints AS9100, ISO 9001, ISO 13485 Certs (2018-Present) – Stop Paying Registrars

Similar on Washingtoner

  • IQSTEL accelerates toward profitability inflection with $317M revenue and AI-driven expansion; IQSTEL Inc. (N A S D A Q: IQST) i
  • AI-Driven Breakthrough Unleashed: Bionic Intelligence Platform Goes Live to Capture Massive Biotech Opportunity: KALA BIO, Inc. (N A S D A Q: KALA)
  • Surging Into Hyper-Growth Mode With Record Revenue, Raised 2026 Guidance, and Game-Changing AI Platform; Off The Hook YS (NYSE American: OTH)
  • Mom Creators Coalition Launches with WaterWipes® as Official Founding Sponsor
  • Daniel Kaufman Expands Kaufman & Company Real Estate Platform With New Acquisitions, AI-Driven Industrial Development and Nationwide Growth Initiative
  • NRx Pharmaceuticals Could Be on the Verge of a Breakout Year as AI, FDA Catalysts, and Mental Health Demand Converge
  • DC Accounting Firm Offers Free Business CRM to Small Business Clients Alongside Weekly Bookkeeping Model
  • Explosive $10 Billion Counter-Drone Market with AI-Powered Defense Ecosystem: ZenaTech, Inc. (N A S D A Q: ZENA)
  • High-Value Execution Phase Begins: Bitcoin Bancorp Ignites Texas Rollout of Digital Asset ATM Network: Bitcoin Bancorp (Stock Symbol: BCBC) $BCBC
  • UK Financial Ltd Tokenized LTNS 1, A $1.1 T Asset-Backed ERC-3643 Security Token with 11 On-Chain Contracts Verifying, Compliant Real-World Value
Copyright © 2026 washingtoner.com | Terms of Service | Privacy Policy | Contact Us | Contribute