Eclypsium launches InfraTrust to flag the infrastructure flaws no one is patching

A new knowledge base and monthly report from firmware security firm Eclypsium aims to tell defenders which router, firewall and server bugs to fix first.

ThreatVectr Newsdesk· 3 min read
Full-frame edge-to-edge photoreal editorial shot of a dimly lit server room aisle, rows of network switches and firewall appliances with amber and green status
Share

Key points

  • Eclypsium launched InfraTrust on release day as a free knowledge base tracking vulnerabilities in infrastructure gear like routers, firewalls, servers and firmware.
  • The company will publish a monthly InfraTrust Pulse report ranking which flaws defenders should patch first.
  • Eclypsium says infrastructure devices are increasingly targeted by state-linked hackers and ransomware crews because they sit outside normal antivirus tools.
  • The service is aimed at security teams struggling to triage thousands of open bugs across network and edge equipment.

Eclypsium, a firm that specialises in the security of firmware (the low-level code baked into hardware like network switches and servers) has launched a new service called InfraTrust.

It is pitched as a free knowledge base for the bits of a company's network most people never see. Think routers, firewalls, VPN boxes, servers and the chips inside them.

Alongside it, Eclypsium will publish a monthly bulletin called InfraTrust Pulse, ranking the infrastructure vulnerabilities that defenders should fix first.

The launch was first reported by BleepingComputer.

Why does another vulnerability list matter?

Because security teams are drowning, and the gear that runs the internet has become a favourite target.

Every week brings fresh bugs in edge devices, meaning the appliances that sit at the boundary between a company's network and the public internet. Firewalls from Fortinet, Ivanti, Cisco and Palo Alto Networks have all been hit hard in the past two years. So have file-transfer servers, VPN concentrators and management interfaces on ordinary office switches.

These devices are attractive to attackers for a simple reason. They are exposed to the internet by design, they often run for years without updates, and most antivirus software cannot see inside them.

Eclypsium argues that defenders lack a clear signal for which of these bugs actually matter. A CVE, which is a public identifier assigned to a software flaw in the format CVE-YYYY-NNNNN, can carry a scary severity score but never be used in a real attack. Another might look mild on paper and end up in every ransomware playbook within a month.

InfraTrust is meant to cut through that noise.

What will the service actually publish?

According to Eclypsium, the knowledge base will track vulnerabilities across four buckets: infrastructure devices, firmware, networking gear and edge equipment.

Each entry is expected to describe the flaw in plain terms, note whether it is being exploited in the wild, and flag which vendors and models are affected. The monthly Pulse report will then pull out the handful of bugs the company believes deserve urgent attention.

That kind of curation already exists elsewhere. The US Cybersecurity and Infrastructure Security Agency runs a Known Exploited Vulnerabilities catalogue at https://www.cisa.gov/known-exploited-vulnerabilities-catalog, which federal agencies must patch on a deadline. Eclypsium's angle is narrower and more technical, focused on the hardware layer where its own products operate.

Who is this for?

Mostly the people who keep large networks running.

Hospital IT teams, bank security staff, government network administrators. The audience is not the general public.

But ordinary people do have a stake here. When a hospital's firewall gets breached through an unpatched flaw, patient records leak. When a telecom's edge router is hijacked, phone calls and text messages can be intercepted. The Salt Typhoon intrusions into US telecom networks last year, blamed on hackers linked to China, hinged on exactly this kind of infrastructure weakness.

Eclypsium is a commercial vendor, so InfraTrust is also a marketing vehicle. The company sells a platform that scans firmware and infrastructure for known issues. A free public feed builds credibility and steers buyers toward its paid products.

Still, defenders will take useful triage wherever they can get it. The queue of unpatched infrastructure bugs is not getting shorter.

© 2026 Threat Vectr