Yuriy Bulygin is CEO and co-founder of Eclypsium.
Adversarial actors are using our network infrastructure against us for cyber espionage operations. And we’re making it easy for them.
Network device exploits are growing faster than NVIDIA’s stock price. According to the 2025 Verizon Data Breach Investigations Report (DBIR) cited by SecurityWeek, firewalls, VPNs, routers, switches and other network infrastructure devices have seen an eightfold increase in vulnerability exploitation over two years, rapidly outpacing credential abuse as an initial intrusion vector.
In a keynote address at the 2026 RSA Conference, Pat Opet, Global Chief Information Security Officer of JPMorgan Chase, said that half of the critical vulnerabilities his team addressed were in network edge devices.
Who is targeting these network edge devices? Often, it is allegedly state-sponsored advanced persistent threat groups that have been sanctioned for targeting American critical infrastructure. Salt Typhoon targeted telecommunications. Volt Typhoon targeted the U.S. Navy, among other targets. Pacific Rim targeted nuclear facilities, state security agencies and more.
All of these attacks compromised network devices like firewalls and VPNs, as well as edge and backbone routers. These devices were used to execute a range of attack tactics, techniques and procedures, from initial access to lateral movement to persistence and data exfiltration.
These attackers are literally inside our firewalls, using our perimeter devices, installed specifically to protect us, against us.
How did we lose our edge?
Using firewalls and VPNs is standard operating procedure for enterprises. Some, like those handling sensitive data subject to HIPAA and other regulations, are legally required to deploy firewalls. And when enterprises purchase large deployments of network infrastructure devices like firewalls and VPNs, they are forced to trust that those vendors that the devices are secure. The vendors have not earned this trust.
There is a small number of large, global vendors that sell network infrastructure devices to enterprises. Cisco. Palo Alto Networks. Fortinet. Arista. Juniper. F5. These vendors create both technical and contractual limitations to their customers’ abilities to examine or modify the functionality of the appliances. Buyers do not get access to the source code of their firewalls, and they cannot install monitoring agents on these devices.
When a vulnerability is disclosed, enterprises have to wait for the vendor to issue a patch. As discovery and exploitation of vulnerabilities accelerate rapidly, trusting and relying on vendors this way is becoming unsustainable.
Additionally, these vendors did not build all of the software that goes into their appliances. The underlying operating system used on most network devices is either Linux or FreeBSD, both of which have numerous actively exploited critical vulnerabilities.
Even vendor-customized versions of these underlying systems are regularly discovered to have actively exploited vulnerabilities, memory-unsafe code and open-source package dependencies.
All of these conditions lead to a situation in which American enterprises are essentially required to purchase network technologies that make it easier, not harder, for foreign threats to break in and sabotage both enterprise interests and our nation’s security.
How can we protect our infrastructure?
Abuse of vulnerable network infrastructure is at least as much of a risk to U.S. interests as abuse of advanced AI models could be. Recognizing the AI risk, the U.S. took decisive action with recent export controls applied to AI models like Mythos.
If the government will step in to restrict the distribution of these models to mitigate cyber risk, then something needs to be done about the massive attack surface that we continue to build in our network infrastructure.
There is no instant fix for this, but “do nothing” is not an option. Vendors have not proven they will proactively deliver truly secure, hardened network infrastructure. So enterprises should take their security and trust into their own hands.
This is what the majority of my conversations are focused on at Eclypsium: securing infrastructure at the edge of AI. While my company works in this space, the specific solution used by security teams is less important than the strategies.
First, enterprises should demand visibility into the network infrastructure devices they purchase. If an organization cannot independently verify what software and firmware is running on a firewall, router or VPN appliance, it is operating on blind trust alone. Security teams need the ability to inventory components, validate firmware integrity, identify vulnerable software, detect unauthorized modifications and continuously monitor these devices throughout their operational lifecycle.
These devices deserve the same continuous monitoring, security validation and operational scrutiny that enterprises already apply to servers and endpoints.
Second, organizations should stop accepting network infrastructure that is a black box that only the vendor can inspect. Network devices are now one of the most common entry points used by nation-state attackers. Defaulting to opacity is unacceptable. In the same presentation we referenced earlier, JPMC’s Pat Opet said his team contacts network vendors twice a day about vulnerabilities in their products. Buyers must insist that their vendors deliver secure products.
Finally, policymakers and critical infrastructure operators need to recognize that this is bigger than the enterprise. Network edge assurance is a national security issue. The U.S. has spent years responding to one campaign after another that exploited the same class of network infrastructure weaknesses. As long as these devices remain opaque and difficult for customers to verify, attackers will continue to find opportunities that defenders cannot easily see.
Attackers have already shown us how they intend to fight. They target the infrastructure we trust the most because it gives them persistence, privileged access and a path around traditional security controls.
Until enterprises and government agencies can independently verify the integrity of the network infrastructure they depend on, we will continue leaving valuable footholds inside our critical systems.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

