Eclypsium Launches InfraTrust for Firmware Patch Priority
Eclypsium's new InfraTrust knowledge base and monthly Pulse report gives network teams a prioritized view of firmware and edge-device vulnerabilities.
There are two patch pipelines in most organizations. The one security teams build process around — operating systems, applications, cloud workloads — arrives with CVSS scores, NVD records, CISA KEV urgency tiers, and vendor SLAs that give it structure even when execution is messy.
The other one runs underneath: routers, switches, firewalls, BMCs, BIOS and UEFI firmware, out-of-band management interfaces, and whatever firmware is embedded in the edge device the network team deployed five years ago and hasn’t touched since. This pipeline is largely unstructured. Scoring systems weren’t designed for it. Vendor patch cycles run longer. Deployment often requires out-of-band access or a maintenance window that never quite arrives. An unpatched flaw in a management BMC or a BGP-speaking router doesn’t respond to apt upgrade. The exposure window is measured in months or years, not weeks.
Eclypsium released InfraTrust on Tuesday — a knowledge base and monthly research publication called the InfraTrust Pulse, focused on vulnerabilities in infrastructure, firmware, networking, and edge devices. The stated purpose is to give security and infrastructure teams a dedicated prioritization layer for a category of exposure that doesn’t fit cleanly into standard software patch workflows.
The structural problem
Standard vulnerability prioritization was built for software in environments where patch delivery is automatable. Firmware differs on almost every axis: longer vendor cycles, limited update tooling in field-deployed devices, complex supply chains (chip vendor, board vendor, OEM integrator, enterprise buyer), and far less telemetry flowing to the places software logging does. An unpatched router firmware flaw doesn’t appear in EDR. A vulnerable BMC doesn’t ship logs to your SIEM.
Eclypsium has documented this territory in prior research: UEFI and BIOS supply-chain integrity, persistent implants in networking equipment, device-level vulnerabilities that sit unpatched for years because nobody has a workflow for them. The InfraTrust knowledge base and monthly Pulse report formalize that output into a standing reference, covering infrastructure firmware, networking equipment, and edge devices, with a focus on actual exploitation priority — not just CVSS arithmetic.
This category doesn’t duplicate what CISA KEV or NVD provide. It supplements the part they don’t reach. The Tenda router backdoor still running unpatched in deployed units illustrates the gap: a vendor-unresponsive flaw in deployed equipment where the standard “wait for the patch, apply it” loop doesn’t close. The N-hour exploitation window problem is real for software; for firmware it doesn’t even get framed that way, because patching cadence is so much slower to begin with.
What to do
Add InfraTrust to the monthly reading list if you manage network infrastructure, edge devices, or hardware where firmware updates require a separate process from your standard software patch cycle. CISA KEV covers the threat-validated software side. InfraTrust is positioned for the physical layer underneath it.
BleepingComputer’s coverage links to the first Pulse report directly: New InfraTrust report reveals infrastructure flaws admins should patch first.
Found this useful? Share it.


