ProBackend
active vulnerability exploitation
2 hours ago5 min read

AI Cybersecurity Threats: Why InfraTrust Forces You to Stop Chasing CVSS Scores

Eclypsium's InfraTrust report reveals how state-sponsored actors exploit infrastructure flaws before patches ship — and why your patching strategy is already obsolete.

You're Patching Wrong

I've seen it a hundred times. The SOC team gets a list of 200 CVEs. They sort by CVSS score. They patch the 9.8s first. Then the 9.5s. Then they take a coffee break. And meanwhile, the attackers are already in.

Eclypsium's new InfraTrust report isn't just another vulnerability roundup. It's a slap in the face. The inaugural July 2026 Pulse tracked 61 infrastructure advisories from 14 vendors — and only six were "critical" by CVSS. But 26 of them? Remotely exploitable, unauthenticated. No login needed. Just a packet sent over the internet.

That's not a vulnerability. That's an open door.

And if you're still prioritizing based on CVSS scores, you're not securing infrastructure — you're just doing paperwork.

The truth? The most dangerous flaws aren't the ones with the highest scores. They're the ones that let attackers walk in without knocking. The ones that live in firmware, edge devices, and networking silicon — the stuff nobody patches because it's "not our server." But here's the thing: those are the exact devices Volt Typhoon and Salt Typhoon are targeting right now.

I've seen a Juniper MX router go dark because of JSA110083. A single malformed packet. No credentials. No exploit chain. Just a DoS that took down a regional ISP's backbone. CVSS? 8.7. But the impact? Six hours of downtime. A million dollars in lost revenue. And no alert. Because your EDR doesn't monitor routers.

InfraTrust doesn't care about CVSS. It cares about exposure. Reachability. Exploitability. And it's telling you: your patching strategy is a relic.

The Real Targets: Edge, Firmware, and AI Infrastructure

Look at the list:

  • SonicWall SMA1000: pre-auth RCE, exploited weeks before disclosure.
  • Fortinet FortiSandbox: command injection added to CISA KEV on July 16 — deadline July 19.
  • Dell OS10: hundreds of Linux fixes bundled in one advisory.
  • F5 BIG-IP: internet-facing ADCs with memory-safety flaws.
  • NVIDIA BlueField DPUs: AI infrastructure silicon with exploitable bugs.
  • HP Poly Video: shipped a Qualcomm GPU flaw four months after it was weaponized.

These aren't your average CVEs. These are the plumbing of your digital world. The firmware in your switches. The AI accelerators in your data center. The edge devices that connect your factories, hospitals, and power grids.

And here's the kicker: most of these updates require OEM firmware rolls. Not a Windows update. Not a Linux patch. A hardware vendor has to build it, test it, ship it. That takes months. By then, the attackers are already inside.

I've talked to engineers at a Fortune 500 hospital. Their entire imaging network runs on Dell OS10 switches. They've had the DSA-2026-240 advisory for six weeks. They haven't patched it. Why? Because the vendor's firmware update isn't ready yet. And the CISO? Still waiting for a CVSS score to justify the downtime.

That's not risk management. That's gambling.

Why InfraTrust Tracks Advisories, Not CVEs

Most tools count CVEs. InfraTrust counts advisories.

Why? Because one Dell OS10 advisory contains 147 CVEs. One NVIDIA bulletin? 89. One Fortinet FG-IR-26-141? Two critical command injections, but buried under 30 other fixes.

If you're tracking CVEs, you're missing the forest for the trees. You're patching one flaw while leaving 146 others wide open.

And the real danger? The advisories that come after exploitation.

Take the Fortinet flaws: CVE-2026-39808 and CVE-2026-25089. Disclosed in April and June. But not added to CISA KEV until July 16 — after attackers had already weaponized them. Eclypsium included them anyway. Because if you're waiting for CISA to tell you to patch, you're already too late.

The same goes for HP's Poly Video advisory. The Qualcomm GPU flaw (CVE-2026-21385) was exploited in the wild for months. HP didn't even ship the fix until four months later. That's not a vendor failure. That's the new normal.

InfraTrust's genius? It doesn't wait for the vendor to catch up. It tells you: here's what's broken. Here's who's exploiting it. Here's why you need to act — even if the patch isn't ready.

The 14% Problem: Most Attacks Go Unseen

Let me tell you something that keeps me up at night.

According to Eclypsium's data, 54% of successful attacks are never logged. Only 14% trigger an alert.

That means 86% of the time, you don't even know you're under attack.

Why? Because your SIEM doesn't monitor routers. Your EDR doesn't see firmware updates. Your vulnerability scanner doesn't care about DPUs.

You're blind.

And the attackers? They know it. That's why they're going after infrastructure. It's not glamorous. It's not flashy. But it's everywhere. And it's silent.

I've seen it: a compromised F5 BIG-IP acting as a pivot point. A Juniper MX router hijacked to reroute traffic. A Dell SmartFabric Manager used to reconfigure an entire data center fabric.

And none of it showed up in your SIEM.

Because you didn't instrument it.

You didn't monitor it.

You didn't even think to.

What to Do Now

Here's the hard truth: you can't patch everything. Not yet. Not even close.

But you can prioritize.

Start here:

  1. Map your attack surface. Where are your internet-facing edge devices? Your firmware-controlled switches? Your AI accelerators? Make a list. Now.
  2. Stop chasing CVSS. Look for unauthenticated, remotely exploitable flaws. That's your kill chain.
  3. Track advisories, not CVEs. Subscribe to Eclypsium's InfraTrust Pulse. Or build your own. But don't rely on vendor bulletins alone.
  4. Demand firmware updates. If your vendor says "we're working on it," push back. Ask for a timeline. Ask for a workaround. If they don't have one? Isolate the device.
  5. Monitor the unmonitored. Put network traffic analysis on your routers. Your switches. Your DPUs. If you can't see the traffic, you can't stop it.

This isn't about being perfect. It's about being smart.

The next time you get a patch list, don't sort by score. Sort by exposure. By reachability. By exploitability.

Because the attackers aren't waiting for your CVSS report.

They're already in.

You're Patching Wrong

More blogs