New Eclypsium data: Attackers are targeting the systems that control infrastructure

Attackers are increasingly going after the systems that control enterprise infrastructure, rather than just the individual devices underneath them.

The latest InfraTrust Pulse from Eclypsium tracked 158 new security advisories covering 1,699 CVEs in less than a month  including 42 Critical advisories, eight perfect 10.0s and 71 remotely exploitable without authentication.

One trend stands out: serious flaws are repeatedly hitting management planes including Cisco FMC and ISE, NVIDIA Unified Fabric Manager, HPE Fabric Composer and other platforms that hold credentials and provide centralized control over infrastructure. The research also highlights how a single Linux kernel flaw has spread across 19 separate vendor advisories, alongside new firmware-level risks including Eclypsium’s recently disclosed UEFI Secure Boot bypass.

You can read the results here: InfraTrust Pulse

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading