Announcing InfraTrust, the source of intelligence on security risks across hardware infrastructure.

Today we’re excited to announce InfraTrust, a global hardware infrastructure security knowledgebase making mission critical infrastructure security data available faster, so you have it when you need it to defend your enterprise. InfraTrust is a searchable, continuously updated source of security advisories and risk data from major enterprise hardware infrastructure vendors.
In addition to the always accessible InfraTrust knowledgebase, we will be issuing a monthly, Patch Tuesday-style digest, summarizing the last 30 days of hardware infrastructure risks captured by InfraTrust, and adding expert commentary, trend analysis, and insights from our team of experts. Watch for InfraTrust Pulse every fourth Wednesday of the month.
We built InfraTrust because infrastructure hardware is increasingly targeted by cyberattackers, and defenders need up-to-date information about threats to their infrastructure as quickly and simply as possible.
Attacks against infrastructure are on the rise, including edge device exploits that have risen eightfold since 2024 according to the Verizon DBIR. The percentage of breaches that involved a network device have tripled. The speed of discovering and exploiting new vulnerabilities is rising, and patching fast enough is getting harder, driven by AI tools like Mythos and open source LLMs.
Until now, security advisories and vulnerability information about hardware infrastructure have been scattered and hard to find. Security teams have to scour dozens of disparate vendor websites to collect necessary security information they use to keep their enterprises secure. As a result, vulnerabilities in the core infrastructure are forgotten or not prioritized. Devices with known exploited vulnerabilities are left unpatched, and the unmonitored attack surface, perfect for adversary stealth and persistence, grows massive.
Furthermore, devices are opaque to security teams. Security tooling has focused on the application layer. EDR and vulnerability management tools don’t look at hardware and components in infrastructure. That makes vendor security advisories a load-bearing information source, often the first or only way to learn of a vulnerability or attack affecting a piece of infrastructure your business runs on.
This was unacceptable to us. As Eclypsium helps global enterprises including top 5 banks and federal agencies secure their infrastructure, we have had front row seats to the onslaught of geopolitically motivated attacks on enterprise infrastructure. Hardware infrastructure is a target for adversaries because it offers a platform for stealth and persistence. Any friction in stopping these attacks is both an enterprise risk and a national security issue.
The Eclypsium platform secures the hardware infrastructure traditional security tools cannot verify. InfraTrust extends that mission to the broader community by making hardware and firmware security intelligence easier to search and use.
Visit Infra-Trust.org to search the world’s first hardware infrastructure security knowledgebase.