Menu
Washingtoner
  • Home
  • Health
  • Business
  • Technology
  • Artificial Intelligence
  • Financial
  • Concealed Carry
  • Non-profit
  • Music
Washingtoner

Cyberpion Reveals A Quarter of Fortune 500 Companies Have Exploitable Vulnerabilities in their External IT Network
Washingtoner/10132666

Trending...
  • Ritz-Carlton Residences Houston Generates Strong Early New Construction Sales at 2120 Post Oak Blvd
  • BlazeHive's AI SEO Agent Outranks Human Writers on 500+ Google Top-3 Results in 5 Months, on Autopilot
  • Cracking the Immortality Code: A Human / AI Long-Term Collaboration Working to Achieve Immortality
KIRKLAND, Wash. and TEL AVIV, Israel, Sept. 14, 2021 /PRNewswire/ -- Cyberpion, a cybersecurity pioneer in external attack surface management (EASM), today presented research showing that nearly three quarters of Fortune 500 companies' IT infrastructure exists outside their organization, a quarter of which was found to have a known vulnerability that threat actors could infiltrate to access sensitive employee or customer data.

Key research findings:
  • 73% of Fortune 500 companies' total IT infrastructure is external to the organization, of which 24% is considered at risk or has a known vulnerability
    • The total IT infrastructure includes the IT assets that are owned and operated by vendors the Fortune 500 enterprises incorporated into their online footprint
    • These IT assets include servers, cloud storage, CDNs, DNS (Domain Name Servers), email servers and other online elements
  • 71% of total cloud-based IT assets are external to the organization, of which 25% failed at least one security test
    • An example of cloud vulnerability includes cloud storage configured to allow anyone to read or write its contents
  • On average, a Fortune 500 company's infrastructure contains 126 different login pages for either customer or employee portals or services - the highest number was over 3,000
    • Nearly 10% of these login pages are considered insecure due to the transmission of unencrypted login data, or issues with SSL certificates, which helps ensure that the submission is being sent to the authorized destination
    • 30% allow transmission over HTTP
    • 12% have invalid certificates/encryption
    • Hackers exploiting these logins could access a wealth of sensitive employee or customer data
  • Fortune 500 organizations connect to an average of 951 cloud assets, of which nearly 5% are vulnerable to severe abuse
    • For example, a misconfigured AWS bucket could allow hackers to read or overwrite the data which could be customer PII or application code
    • The largest exposure was well over 30K cloud assets

Cyberpion collected these results by performing a cursory single-pass scan of the public and internet-facing assets of every Fortune 500 company in the first half of 2021.

More on Washingtoner
  • New Book, The KI of Marketing, Helps Small Businesses Grow Without Trying to Outspend Bigger Competitors
  • ExtraCarry Adds .327 Federal Magnum to Speed Strip Pocket Holder Lineup
  • Tacoma: Street Closures Projected to Start August 25 for Residential Street Restoration Program Maintenance Work
  • Food Journal Magazine Focuses Its Los Angeles Dining Coverage Across Three Editorial Verticals
  • Gravity Payments and Suno Software Partner to Simplify Payments for Independent Hearing Clinics

According to Gartner1, "EASM is an emerging concept that is growing quickly in terms of awareness within the security vendor community but at a slower pace within end-user organizations...They help security professionals identify exposed vulnerabilities from known and unknown enterprise assets and prioritize the most critical issues to be tackled...EASM should be part of a broader vulnerability and threat management effort aimed at discovering and managing internal- and external-facing assets and their potential vulnerabilities."

Traditional third-party risk management solutions have focused exclusively on the vendors and the IT infrastructures that are directly connected to the enterprise. This approach ignores the true scale of the problem and represents only the tip of the iceberg. Third-party vendors have also adopted a distributed IT infrastructure, and have built their applications and services using their own vendors and third-parties. Those in turn build their solutions upon even more partners. This extensive ecosystem creates an external attack surface that is uniquely appealing to hackers to attack, and extremely complicated for enterprises to manage securely.

Hackers are finding it easier to takeover or exploit the vulnerabilities in the third-party assets within the enterprise's ecosystem in order to carry out attacks such as: malicious code injection (Magecart-style attacks), DNS hijacks, or abusing the branded assets of an enterprise. These breaches ultimately lead to data loss, brand reputation damage, and stolen customer data for the enterprise.

"Security teams often can't effectively defend against attacks stemming from third-parties because they lack visibility into the total inventory and volume of assets they are connected to," said Cyberpion CEO Nethanel Gelertner. "They are unaware of the exposure to these external vulnerabilities, and can't identify and mitigate against these risks. In addition, the growth of these interconnected assets continues to explode due to trends in cloud-first architectures and digital transformation initiatives, meaning that assessing and protecting the attack surface has become even more challenging over time."

More on Washingtoner
  • Where Do Missouri Plane Crashes Really Happen? Not Where You'd Think
  • Spokane: Female Arrested After Homeowners Caught Her on Property of Burned Home
  • SPD Detectives are Investigating a Suspicious Death in West Spokane
  • LCC Asia Pacific Sponsors CubeSatPlus 2026 at UNSW Sydney
  • Spokane: City Council Approves Mayor's Orders for Declaration of Emergency

About Cyberpion

Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets that form an external attack surface. Knowing how your organization is vulnerable, where those threats come from, and what infrastructures are at risk, is critical to preventing an attack before it happens. Cyberpion helps organizations mitigate these advanced threats by continuously monitoring, discovering, and assessing the threat vectors present throughout online ecosystems that exist outside the traditional security perimeter. With an R&D team based in Israel, the company is funded by leading cybersecurity venture capitalists. To learn more, visit cyberpion.com.

For more information, please contact:
Josh Turner
Si14 Global Communications
josh.[email protected]

1 Gartner, "Emerging Technologies: Critical Insights for External Attack Surface Management" by Ruggero Contu, Elizabeth Kim and Mark Wah, March 19, 2021

SOURCE Cyberpion
Show All News | Disclaimer | Report Violation

0 Comments
1000 characters max.

Latest on Washingtoner
  • Paula Josephine Sadler Releases "Imagine" on 24th Anniversary of Sobriety
  • Ritz-Carlton Residences Houston Generates Strong Early New Construction Sales at 2120 Post Oak Blvd
  • No Sugar Baker Continues National Growth with Seattle Market Expansion Across Washington, Idaho, and Alaska
  • The Refugee Archive Launches Campaign to Preserve 21 Female-Headed Household Oral Histories in Rebel-Controlled Goma
  • Space Ambitions Expanding as New Testing Builds on NASA Results and Targets MEO, GEO and Next-Generation Orbital Markets: Ascent Solar Technologies
  • FDA Path Clears, Manufacturing Ramps Up + $22.3 Million Strengthens the Balance Sheet; Inflection Point for NRx Pharmaceuticals (N A S D A Q: NRXP)
  • Buy Retatrutide Research Peptide: Why Reta Is Getting So Much Attention
  • Stage 2 Burn Ban Order in Effect Across Tacoma
  • San Diego Attorney Anthony Z. Vargas Narrows Practice to Employment Law, Representing Employees Only
  • Spokane: Additional PPE Kits Available Tuesday and Thursday
  • Solid Earth Introduces RealtyID, a Universal Identity Spine for the Real Estate Industry
  • BlazeHive's AI SEO Agent Outranks Human Writers on 500+ Google Top-3 Results in 5 Months, on Autopilot
  • Cracking the Immortality Code: A Human / AI Long-Term Collaboration Working to Achieve Immortality
  • On the Boards: Proform Builds Announce New Construction in Alki, Seattle
  • On the Boards: Proform Builds Announce New Construction in Gig Harbor
  • Phinge Exposes Massive AI Security Risks, Claiming Its Patented Hardware-Verified Architecture Is The Only Safeguard Against Surveillance Capitalism
  • Phinge & CEO Robert DeMaio Publicly Declare Cash Settlements or Judgments Alone Cannot & Will Not Remedy the Deep Public Harm of Infringing Its IP
  • Dana Flanagan Expands the Authority Architect, Bringing a Nontraditional Approach to Executive Authority, Strategic Access and Business Growth
  • Phinge's Netverse: Reclaiming the Digital Frontier For Everyone Through CEO Robert DeMaio's Vision of a True App-less, User Data Sovereign World
  • DuraFast Label Company Launches Seiko SLP850 2" Thermal Printer with Free Label Promotion
_catLbl0 _catLbl1

Popular on Washingtoner

  • Heritage at South Brunswick Introduces New Ferndale Floorplan: The Largest Single-Family Home Design in the Community - 465
  • Spokane: SPD Arrest Level III Registered Sex Offender for Failure to Register - 271
  • Tacoma: Applications Now Being Accepted for three Positions on the Urban Design Board - 111
  • Leeds Billboard Campaign Drives 188% Traffic Uplift as AI Enquiries Rise 266% for Loud! OOH
  • Final Week for Spokane Falls Boulevard Survey
  • Omnitronics launches Ecosystem Health Dashboard to enable proactive monitoring across dispatch environments
  • Crossroads4Hope Announces The Lipschutz Women's Fund
  • KeysCaribbean Resorts Offer Savings On Summer Vacations Now Through Aug. 31
  • Tacoma: Hylebos Bridge Closed to Vehicular Traffic
  • Spokane: SPD is Seeking Assistance in Locating Missing Adult Male

Similar on Washingtoner

  • Black Dog Venture Partners and VC Fast Pitch to Host "San Francisco Investors and Innovators" Networking Event
  • Real Estate Syndication Attorney Tilden Moschetti Releases The Real Estate Private Equity Blueprint
  • 5X Gross Margin Improvement to Beat EPS Consensus; $54.6 Million 10-Year Contract Award Puts Cybersecurity Leader on Path to a $30 Million Run Rate
  • Tallahassee Million-Dollar Home Sales Rise in 2026 as Median Selling Time More Than Doubles
  • Slotozilla Reports Strong Growth in Q2 2026
  • Space Ambitions Expanding as New Testing Builds on NASA Results and Targets MEO, GEO and Next-Generation Orbital Markets: Ascent Solar Technologies
  • FDA Path Clears, Manufacturing Ramps Up + $22.3 Million Strengthens the Balance Sheet; Inflection Point for NRx Pharmaceuticals (N A S D A Q: NRXP)
  • BlazeHive's AI SEO Agent Outranks Human Writers on 500+ Google Top-3 Results in 5 Months, on Autopilot
  • Dana Flanagan Expands the Authority Architect, Bringing a Nontraditional Approach to Executive Authority, Strategic Access and Business Growth
  • DuraFast Label Company Launches Seiko SLP850 2" Thermal Printer with Free Label Promotion
Copyright © 2026 washingtoner.com | Terms of Service | Privacy Policy | Contact Us | Contribute