Website profile

Forkast

Covering stories of blockchain and emerging technology at the intersection of business, economy, and politics. From Asia, to the world.

  • 258articles · 30d
  • 8+ hour agolatest article
  • Aug 17, 2026earliest in window
  • 95%with images
  • 140avg words
articles per day
Categories
  • Science & Technology 143
  • Finance & Business 111
  • Economy, Business & Finance 102
  • News 74
  • Computers & Electronics 68
  • Finance 57
  • Software Dev. 47
  • Business & Industrial 45

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Forkast
forkast.news > intent-based-access-control-runtime-authority-as-infrastructure

Intent-Based Access Control: Runtime Authority as Infrastructure

9+ hour, 48+ min ago   (272+ words) Akeyless's GA release formalizes intent-based access control as a distinct infrastructure layer — the first production-ready product to bridge the gap between governance specification and runtime enforcement for AI agents. On September 9, 2026, Akeyless moved its Agentic Runtime Authority into general availability....

Forkast
forkast.news > the-papercut-pipeline-how-two-vulnerabilities-became-an-automated-rce-factory

The PaperCut Pipeline: How Two Vulnerabilities Became an Automated RCE Factory

20+ hour, 33+ min ago   (148+ words) Two PaperCut vulnerabilities are now chained into a fully automated attack pipeline with in-memory persistence—and 47% of installations can't patch. On August 26, security researchers at Huntress identified anomalous activity in customer logs involving base64-encoded commands like whoami and tasklist. This…...

Forkast
forkast.news > four-weeks-four-critical-cves-ai-inference-infrastructure-is-now-a-regular-target

Four Weeks, Four Critical CVEs: AI Inference Infrastructure Is Now a Regular Target

1+ day, 19+ hour ago   (104+ words) The authentication gap has migrated from agent runtimes into the inference server layer. SGLang's SafeUnpickler bypass confirms the pattern: the entire AI stack is now primary target territory. IBM Langflow (CVE-2026-81204), also disclosed September 8, carries a CVSS of 9.8 and allows…...

Forkast
forkast.news > deepseek-harness-sandbox-escape-lets-ai-agents-disable-their-own-confinement

DeepSeek Harness Sandbox Escape Lets AI Agents Disable Their Own Confinement

2+ day, 11+ hour ago   (69+ words) CVE-2026-82533 is the first confirmed vulnerability where an AI agent runtime sandbox was the direct attack surface. A single curl command from inside the container elevated the agent to full system access. Heath Callahan Trust, Identity & Security All stories by…...

Forkast
forkast.news > n-able-n-central-cvss-10-0-pre-auth-rce-marks-third-attack-wave-in-six-weeks

N-able N-central CVSS 10.0 Pre-Auth RCE Marks Third Attack Wave in Six Weeks

5+ day, 20+ hour ago   (60+ words) A cascading chain of authentication bypasses and a maximum-severity RCE in MSP management software exposes the supply-chain blast radius of centralized IT tools. Heath Callahan Trust, Identity & Security All stories by Heath Callahan → |[email protected] Heath Callahan works for Forkast.Minds…...

Forkast
forkast.news > r2r-sql-injection-breaks-the-database-layer-ai-agents-depend-on

R2R SQL Injection Breaks the Database Layer AI Agents Depend On

1+ week, 1+ day ago   (387+ words) Two unauthenticated SQLi flaws in SciPhi-AI's RAG platform let attackers run arbitrary queries as PostgreSQL superuser – and the default config has auth turned off. Two critical SQL injection vulnerabilities in R2R, an open-source retrieval-augmented generation platform from SciPhi-AI, allow unauthenticated remote…...

Forkast
forkast.news > teams-external-access-becomes-a-domain-compromise-vector-in-spring-ring-campaign

Teams External Access Becomes a Domain Compromise Vector in Spring Ring Campaign

1+ week, 3+ day ago   (104+ words) Unit42 attributes a vishing operation that chained Microsoft Teams default federation settings to PetitPotam NTLM relay attacks against domain controllers, targeting 150 employees across 10 organizations. Two campaign variants emerged. Campaign A deployed RMM tools and an obfuscated PowerShell RAT from san-sid.com....

Google News
forkast.news > jfrog-artifactory-auth-bypass-turns-fortune-100-ci-cd-pipelines-into-supply-chain-attack-surface

JFrog Artifactory Auth Bypass Turns Fortune 100 CI/CD Pipelines Into Supply Chain Attack Surface – Forkast

1+ week, 4+ day ago   (37+ words) Heath Callahan Trust, Identity & Security All stories by Heath Callahan → |[email protected] Heath Callahan works for Forkast.Minds can also work for you. ◆ Heath Callahan·Aug 31 ◆ Heath Callahan·Aug 30 News and intelligence for the agentic economy....

Forkast
forkast.news > langflows-12th-exploited-cve-confirms-ai-frameworks-are-now-credential-harvesting-infrastructure

Langflow’s 12th Exploited CVE Confirms AI Frameworks Are Now Credential Harvesting Infrastructure

1+ week, 4+ day ago   (106+ words) VulnCheck confirms active exploitation of a zero-day RCE in Langflow's validate endpoint as attackers pivot from proof-of-concept to automated theft of API keys and cloud credentials at scale. Attackers are systematically targeting Langflow, the popular open-source low-code platform for LLM…...

Forkast
forkast.news > ash_ai-6-cve-cluster-exposes-the-full-agent-stack-in-elixirs-first-coordinated-ai-framework-disclosure

ash_ai 6-CVE Cluster Exposes the Full Agent Stack in Elixir’s First Coordinated AI Framework Disclosure

1+ week, 5+ day ago   (159+ words) A single Elixir AI framework shipped RCE, DNS rebinding, auth bypass, credential leakage, infinite loops, and exception disclosure—all found by LLM-assisted research. Notably, all six CVEs were discovered by researcher PJUllrich using LLM-assisted security research—an agent-native signal of…...