Eclypsium Launches InfraTrust Amid Surge in Hardware Vulnerabilities

Eclypsium Launches InfraTrust Amid Surge in Hardware Vulnerabilities

First seen 22 Jul 2026, 15:26 UTC BleepingcomputerSg.Finance.Yahoopulse.infra-trust.orgfortiguard.fortinet.com 89% similarity 76.5

Article Content

Browse articles
ThreatCluster

Eclypsium has launched InfraTrust, a centralized resource for infrastructure cybersecurity, amid increasing exploitation of hardware vulnerabilities. The inaugural InfraTrust Pulse report reveals 61 advisories from 14 vendors, including six critical vulnerabilities and 26 remotely exploitable flaws. Notably, CVE-2026-15409 and CVE-2026-15410 were actively exploited before their public disclosure. The report emphasizes the need for organizations to prioritize vulnerabilities based on exploitability and exposure rather than traditional severity scores. The rise in attacks on edge devices and VPNs has prompted this initiative, as state-sponsored actors from Russia and China have targeted these systems. The report aims to provide actionable intelligence to help organizations secure their infrastructure effectively.

Key Points: • Eclypsium's InfraTrust consolidates security advisories for hardware vulnerabilities. • 61 advisories were tracked, including six critical vulnerabilities and 26 remotely exploitable flaws. • CVE-2026-15409 and CVE-2026-15410 were exploited before public disclosure, highlighting urgent patching needs.

ThreatCluster AI

Timeline

2026-03-02
CVE-2026-21385 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-15409 published
A remote code execution vulnerability in SonicWall's SMA1000 was disclosed, leading to active exploitation.
BleepingComputer
2026-07-14
CVE-2026-15410 published
Another critical vulnerability in SonicWall's SMA1000 was disclosed, also leading to active exploitation.
BleepingComputer
2026-07-16
CVE-2026-25089 added to CISA KEV
A critical command injection vulnerability in Fortinet's FortiSandbox was added to the Known Exploited Vulnerabilities catalog.
BleepingComputer
2026-07-16
CVE-2026-39808 added to CISA KEV
Another critical vulnerability in Fortinet's FortiSandbox was added to the Known Exploited Vulnerabilities catalog.
BleepingComputer
2026-07-22
InfraTrust launched
Eclypsium launched InfraTrust, a centralized resource for infrastructure cybersecurity, to address rising hardware vulnerabilities.
Sg.Finance.Yahoo

Community

Browse all →