Menu
Washingtoner
  • Home
  • Business
  • Transportation
  • Aerospace
  • Boeing
  • Technology
  • Construction
  • Health
  • Kelly Ortberg
Washingtoner

Cyberpion Reveals A Quarter of Fortune 500 Companies Have Exploitable Vulnerabilities in their External IT Network
Washingtoner/10132666

Trending...
  • NIUFO Examines European MiCA Regulation's Impact on Digital Asset Trading Markets
  • AHRFD Releases Market Analysis: Cryptocurrency Market's Institutional Transformation Accelerating
  • Ubleu Crypto Group Analyzes European Digital Asset Market Opportunities Amid Regulatory Evolution
KIRKLAND, Wash. and TEL AVIV, Israel, Sept. 14, 2021 /PRNewswire/ -- Cyberpion, a cybersecurity pioneer in external attack surface management (EASM), today presented research showing that nearly three quarters of Fortune 500 companies' IT infrastructure exists outside their organization, a quarter of which was found to have a known vulnerability that threat actors could infiltrate to access sensitive employee or customer data.

Key research findings:
  • 73% of Fortune 500 companies' total IT infrastructure is external to the organization, of which 24% is considered at risk or has a known vulnerability
    • The total IT infrastructure includes the IT assets that are owned and operated by vendors the Fortune 500 enterprises incorporated into their online footprint
    • These IT assets include servers, cloud storage, CDNs, DNS (Domain Name Servers), email servers and other online elements
  • 71% of total cloud-based IT assets are external to the organization, of which 25% failed at least one security test
    • An example of cloud vulnerability includes cloud storage configured to allow anyone to read or write its contents
  • On average, a Fortune 500 company's infrastructure contains 126 different login pages for either customer or employee portals or services - the highest number was over 3,000
    • Nearly 10% of these login pages are considered insecure due to the transmission of unencrypted login data, or issues with SSL certificates, which helps ensure that the submission is being sent to the authorized destination
    • 30% allow transmission over HTTP
    • 12% have invalid certificates/encryption
    • Hackers exploiting these logins could access a wealth of sensitive employee or customer data
  • Fortune 500 organizations connect to an average of 951 cloud assets, of which nearly 5% are vulnerable to severe abuse
    • For example, a misconfigured AWS bucket could allow hackers to read or overwrite the data which could be customer PII or application code
    • The largest exposure was well over 30K cloud assets

Cyberpion collected these results by performing a cursory single-pass scan of the public and internet-facing assets of every Fortune 500 company in the first half of 2021.

More on Washingtoner
  • Tacoma: Applicants Sought for the Landmarks Preservation Commission
  • Steward's Plumbing Sponsors the 2025 Samson Challenge, Bringing Community, Fitness, and Fun Together in Albuquerque
  • 10xLaw.com Extends Employment Opportunity to Kim Kardashian
  • DecisionPoint Technologies Accelerates Growth with Acquisition of Acuity Technologies
  • CCHR: Involuntary Commitment Is Eugenics Repackaged as "Mental Health Care"

According to Gartner1, "EASM is an emerging concept that is growing quickly in terms of awareness within the security vendor community but at a slower pace within end-user organizations...They help security professionals identify exposed vulnerabilities from known and unknown enterprise assets and prioritize the most critical issues to be tackled...EASM should be part of a broader vulnerability and threat management effort aimed at discovering and managing internal- and external-facing assets and their potential vulnerabilities."

Traditional third-party risk management solutions have focused exclusively on the vendors and the IT infrastructures that are directly connected to the enterprise. This approach ignores the true scale of the problem and represents only the tip of the iceberg. Third-party vendors have also adopted a distributed IT infrastructure, and have built their applications and services using their own vendors and third-parties. Those in turn build their solutions upon even more partners. This extensive ecosystem creates an external attack surface that is uniquely appealing to hackers to attack, and extremely complicated for enterprises to manage securely.

Hackers are finding it easier to takeover or exploit the vulnerabilities in the third-party assets within the enterprise's ecosystem in order to carry out attacks such as: malicious code injection (Magecart-style attacks), DNS hijacks, or abusing the branded assets of an enterprise. These breaches ultimately lead to data loss, brand reputation damage, and stolen customer data for the enterprise.

"Security teams often can't effectively defend against attacks stemming from third-parties because they lack visibility into the total inventory and volume of assets they are connected to," said Cyberpion CEO Nethanel Gelertner. "They are unaware of the exposure to these external vulnerabilities, and can't identify and mitigate against these risks. In addition, the growth of these interconnected assets continues to explode due to trends in cloud-first architectures and digital transformation initiatives, meaning that assessing and protecting the attack surface has become even more challenging over time."

More on Washingtoner
  • Q2 2025 Industry Impact Report Underscores Semiconductor Expansion, Talent Development and Sustainability Milestones
  • 84 Ethiopian Churches Change Signboards to Shincheonji Church of Jesus
  • AI-Powered Websites to Help Contractors Increase Revenue
  • Rybak & Company, LLC: Trusted General Contractor in Camas and Vancouver, WA
  • BTXSGG Outlines Four-Pillar Framework to Enhance Digital Asset Security and Compliance

About Cyberpion

Cyberpion solves the rising cybersecurity challenge of understanding the risks and vulnerabilities of your connected online assets that form an external attack surface. Knowing how your organization is vulnerable, where those threats come from, and what infrastructures are at risk, is critical to preventing an attack before it happens. Cyberpion helps organizations mitigate these advanced threats by continuously monitoring, discovering, and assessing the threat vectors present throughout online ecosystems that exist outside the traditional security perimeter. With an R&D team based in Israel, the company is funded by leading cybersecurity venture capitalists. To learn more, visit cyberpion.com.

For more information, please contact:
Josh Turner
Si14 Global Communications
josh.[email protected]

1 Gartner, "Emerging Technologies: Critical Insights for External Attack Surface Management" by Ruggero Contu, Elizabeth Kim and Mark Wah, March 19, 2021

SOURCE Cyberpion
Filed Under: Business

Show All News | Report Violation

0 Comments
1000 characters max.

Latest on Washingtoner
  • New Slotozilla Project Explores What Happens When the World Goes Silent
  • The Two Faces of Charles D. Braun: How the Novel, Posthumously Yours, Came to Life
  • Spokane: Flags at Half-Staff Honoring Victims of Political Violence
  • Spokane: Flags at Half-Staff In Remembrance of 9/11
  • Counseling Center of New Smyrna Beach Expands Affordable Mental Health Services for Volusia County
  • Athena Forge (ATFG) Introduces Advanced Token for Technology-Driven Financial Ecosystem
  • Albuquerque's Z-CoiL Footwear Brings All-American Family Business Story to Shark Tank Season Premiere
  • NoviSign Sponsoring VARTECH 2025 - the B2B IT channel's #1 event
  • Unicorp and BH Group Select Chasing Creative—Palm Coast Agency—to Lead Growth Marketing for The Ritz-Carlton Residences, Hammock Dunes
  • Breaking: 50+ runners from 20+ states relay custom 9/11 flag 485 miles from Shanksville through DC to Ground Zero for memorial remembrance run
  • SecureMaine 2025 is this October 8th in Portland, Maine
  • John Thomas calls for unity and prayer after tragic loss
  • Where the Miami Dolphins Stand After Week 1
  • Which NFL Teams Can Rebound from Week 1? OddsTrader Breaks Down the Biggest Questions
  • South Tacoma Groundwater Protection District Code Updates Adopted by the Tacoma City Council
  • Apellix Deploys Breakthrough Spray-Painting Drones into Live Service Limited Beta Program Open for Advanced Contractors
  • DivX Unveils New Educational Blog Series to Simplify MKV to MP4 Video Conversion
  • SKYLAR DIGGINS ADVANCES TO PLAYOFFS AFTER WEARING 422 GRAMS OF PROTEIN--MADE WITH MILK
  • CCHR: For Prevention, Families Deserve Truth From NIH Study on Psychiatric Drugs
  • Sheets.Market Brings Professional Financial Model Templates to Entrepreneurs and Startups
_catLbl0 _catLbl1

Popular on Washingtoner

  • $5 - $20 Million in Sales for 2026; $25 - $40 Million for 2027 Projected with NASA Agreements; New MOU Signed to Improve Solar Tech in Space - 815
  • OddsTrader Asks: What Are the Chances Your Team Makes the NFL Playoffs? - 285
  • Iterators Named Preferred Accessibility Testing Vendor by MIT - 212
  • Benchmark International Successfully Facilitated the Trans of Bison Gardens and an Undisclosed Buyer - 201
  • Heritage at South Brunswick Announces Two New Building Releases In Townhome Collection - 184
  • Unlocking Amazon Savings: How Seller Promotional Codes Work — And How to Find Them Legitimately - 168
  • SQUARESIGNS Featured in Inc.5000 List Again - 145
  • Only 7 Days Left for Early Bird Registration to the OpenSSL Conference 2025 - 131
  • Assent Joins AWS ISV Accelerate Program - 120
  • University of South Pacific and Battery Pollution Technologies Forge Strategic Partnership to tackle Battery End-of-Life Challenges in the Pacific - 102

Similar on Washingtoner

  • Physician-Turned-Patient Launches Advocacy Campaign to Spotlight Disability Insurance Barriers
  • Youth Take the Lead: Kopp Foundation for Diabetes Hosts "By Youth, For Youth, With T1D" Gala on October 8 at Blue Bell Country Club
  • "Leading From Day One: The Essential Guide for New Supervisors" Draws from 25+ Years of International Management Experience
  • REI's Member Days bring 11 days of exclusive offers and expanded benefits to get outside
  • New Slotozilla Project Explores What Happens When the World Goes Silent
  • Albuquerque's Z-CoiL Footwear Brings All-American Family Business Story to Shark Tank Season Premiere
  • Unicorp and BH Group Select Chasing Creative—Palm Coast Agency—to Lead Growth Marketing for The Ritz-Carlton Residences, Hammock Dunes
  • SecureMaine 2025 is this October 8th in Portland, Maine
  • Where the Miami Dolphins Stand After Week 1
  • Which NFL Teams Can Rebound from Week 1? OddsTrader Breaks Down the Biggest Questions
Copyright © 2025 washingtoner.com | Terms of Service | Privacy Policy | Contact Us | Contribute