Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Forkast
forkast.news > vpn-infrastructure-is-now-the-authentication-gaps-final-frontier

VPN Infrastructure Is Now the Authentication Gap’s Final Frontier

1+ hour, 13+ min ago   (66+ words) Previdian recorded 10 exploitation attempts from six attacker IPs within 24 hours of a public PoC release. The 15-day patch-to-exploitation window shows threat actors weaponizing Citrix disclosures faster than enterprises can deploy fixes. Heath Callahan Trust, Identity & Security All stories by Heath…...

Forkast
forkast.news > deepseeks-new-architecture-slashes-agentic-costs-by-80

DeepSeek’s New Architecture Slashes Agentic Costs by 80%

1+ hour, 5+ min ago   (128+ words) A Causal Encoder-Decoder design compresses cache-hit costs to $0.003 per token and retires V4-Pro, forcing a recalibration of the agent economy's pricing structure. These developments occur as DeepSeek, now carrying a $71 billion valuation, continues to push the limits of Chinese open-weight…...

Forkast
forkast.news > 79-of-multi-agent-failures-are-specification-problems-and-the-new-protocol-stack-isnt-solving-that-layer

79% of Multi-Agent Failures Are Specification Problems – And the New Protocol Stack Isn’t Solving That Layer

1+ hour, 42+ min ago   (76+ words) UC Berkeley's MAST taxonomy shows the vast majority of multi-agent system failures stem from how agents are designed and specified, not from model limits. The industry's runtime enforcement stack addresses the easier half of the problem. Blair Hayes Agent Infrastructure…...

Forkast
forkast.news > citrix-netscaler-authentication-bypass-under-active-exploitation-vpn-infrastructure-joins-the-authentication-gap

Citrix NetScaler Authentication Bypass Under Active Exploitation – VPN Infrastructure Joins the Authentication Gap

9+ hour, 57+ min ago   (66+ words) Previdian recorded 10 exploitation attempts from six attacker IPs within 24 hours of a public PoC release. The 15-day patch-to-exploitation window shows threat actors weaponizing Citrix disclosures faster than enterprises can deploy fixes. Heath Callahan Trust, Identity & Security All stories by Heath…...

Forkast
forkast.news > check-point-quantum-vpn-drops-two-cvss-9-8-cves-in-the-same-certificate-path-vpn-infrastructure-joins-the-auth-gap

Check Point Quantum VPN Drops Two CVSS 9.8 CVEs in the Same Certificate Path – VPN Infrastructure Joins the Auth Gap

14+ hour, 33+ min ago   (144+ words) Two pre-authentication RCEs in VPN certificate handling extend the authentication gap from middleware and ERP into the infrastructure layer that secures remote enterprise access. The vulnerabilities exist within the same certificate verification layer, specifically during the VPN negotiation phase before…...

Forkast
forkast.news > ivantis-september-patch-day-drops-two-authentication-bypasses-endpoint-management-is-now-part-of-the-gap

Ivanti’s September Patch Day Drops Two Authentication Bypasses – Endpoint Management Is Now Part of the Gap

20+ hour, 29+ min ago   (58+ words) Sentry and EPMM join PaperCut, N-able, Microsoft, and SAP as the latest enterprise management tools where authentication fails before the system checks who is asking. Heath Callahan Trust, Identity & Security All stories by Heath Callahan → |[email protected] Heath Callahan works for…...

Forkast
forkast.news > saps-september-patch-day-drops-four-critical-cves-three-of-them-bypass-authentication-entirely

SAP’s September Patch Day Drops Four Critical CVEs—Three of Them Bypass Authentication Entirely

1+ day, 1+ hour ago   (155+ words) OVERPASS and S4GET enable unauthenticated RCE on core ERP infrastructure. The authentication gap is no longer a middleware problem. SAP’s September 2026 Patch Day dropped 19 new security notes on September 8, and four of them carry Critical severity. Three involve the same structural…...

Forkast
forkast.news > metas-muse-launches-as-the-biggest-cross-app-ai-agent-yet-with-a-security-disclosure-problem

Meta’s Muse Launches as the Biggest Cross-App AI Agent Yet—With a Security Disclosure Problem

1+ day, 10+ hour ago   (67+ words) The company is asking consumers to trust the least-trusted tech platform with the most access any agent has ever required, at a premium price. Internal testing tells a different story. Mila Cohen Agents at Home All stories by Mila Cohen…...

Forkast
forkast.news > microsofts-two-track-patch-tuesday-cloud-identity-flaws-fixed-before-disclosure-windows-still-catching-up

Microsoft’s Two-Track Patch Tuesday: Cloud Identity Flaws Fixed Before Disclosure, Windows Still Catching Up

1+ day, 16+ hour ago   (121+ words) The September 8 batch covers 70 CVEs including Windows Secure Kernel Mode and VBS vulnerabilities. But the most critical identity flaws—Azure AD B2C and Entra ID at CVSS 10.0—were silently fixed five days earlier, all server-side, no customer action required. In response…...

Forkast
forkast.news > trezors-supply-chain-cracked-through-shipmonks-unpatched-metabase-67000-crypto-customers-exposed

Trezor’s Supply Chain Cracked Through ShipMonk’s Unpatched Metabase: 67,000 Crypto Customers Exposed

2+ day, 15+ hour ago   (107+ words) The authentication gap pattern reaches into crypto supply chains—not through the wallet, but through the fulfillment warehouse's business intelligence tool. The entry point was CVE-2026-72898, an unauthenticated SQL injection in Metabase’s password reset endpoint carrying a CVSS score of…...