← All stories
● Covered by 1 source · 1 reportMedium impact

Eclypsium launches InfraTrust report for prioritizing infrastructure vulnerabilities

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Eclypsium released InfraTrust and its inaugural Pulse report to help organizations prioritize infrastructure vulnerabilities. The report focuses on exploitability and real-world impact rather than just severity scores, highlighting flaws from key vendors that require urgent attention.

Key points

  • Eclypsium's InfraTrust provides a monthly report on infrastructure vulnerabilities.
  • First report tracked 61 advisories from 14 vendors with several critical risks.
  • Focus on exploitability and exposure is vital amid increasing attacks by state-sponsored actors.

Introduction of InfraTrust

Eclypsium has launched InfraTrust, a new cybersecurity knowledge base and the InfraTrust Pulse report. This initiative aims to help organizations effectively prioritize vulnerabilities present in their infrastructure, firmware, networking, and edge devices.

Inaugural InfraTrust Pulse Report

The inaugural report, released in July 2026, aggregated data from 61 infrastructure advisories from 14 different vendors. Among these, it flagged six as critical and noted 26 vulnerabilities that are remotely exploitable without authentication.

Focus on Exploitability

Eclypsium emphasizes that vulnerabilities should be prioritized based on factors like exploitability, reachability, and exposure rather than solely relying on traditional severity scores such as CVSS. This shift comes in response to the rising vulnerabilities targeted by state-sponsored threat actors.

Critical Advisories Highlighted

The report identifies key advisories that require urgent action. For instance, SonicWall SMA1000 vulnerabilities (CVE-2026-15409 and CVE-2026-15410) were exploited even before their disclosure. Similarly, Fortinet's earlier disclosed critical vulnerabilities were also flagged for immediate attention.

Threat Landscape and Implications

The release of the InfraTrust report coincides with increasing attacks on infrastructure devices by entities linked to Russian and Chinese states. These groups have exploited existing flaws in critical infrastructure and networking devices, making the need for effective vulnerability management crucial.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~39 min · 35 stories · Jul 22

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Eclypsium released InfraTrust and its inaugural Pulse report to help organizations prioritize infrastructure vulnerabilities. The report focuses on exploitability and real-world impact rather than just severity scores, highlighting flaws from key vendors that require urgent attention.