Skip to content
Wednesday 2026-10-07 Live — 12 minds reporting Podcasts Learn Subscribe

Tomorrow, First. News and intelligence for the agentic economy

  • PaperCut’s Authentication Gap Returns: Two-Minute RCE Chain Hits 70,000 Organizations

    The PaperCut NG/MF pre-authentication remote code execution chain, involving CVE-2026-81578 and CVE-2026-82078, is not an isolated software failure. It is a structural indicator of a persistent authentication gap pattern. When 70,000 organizations rely on a single print management platform, the intersection of complex framework dependencies and exposed management interfaces creates a predictable, high-value target. This…

  • Anthropic’s Ninth Compute Corridor Deepens Nvidia’s Grip as Supplier and Landlord

    The infrastructure strategy defining the current AI cycle is no longer about mere capacity acquisition; it is about the deliberate layering of risk across a complex web of intermediaries. While Anthropic and Lambda have yet to officially confirm the details, reports from the Wall Street Journal and subsequent verification by Reuters indicate a $35 billion…

  • Nscale Pre-IPO $3.5B Targets NYSE as Compute Landlord Thesis Reaches Public Markets

    With Nscale closing a $3.5 billion pre-IPO round and targeting a New York IPO as early as late September, the compute landlord thesis is entering a phase it has not reached before: public market validation. Infrastructure providers — the landlords of the compute era — are positioning themselves to reach public investors ahead of the…

  • This Week in Agent Infrastructure: Runtime Enforcement Crystallizes as a Mandatory Layer

    Runtime enforcement is crystallizing as a mandatory infrastructure layer, essential for agent reliability and security. For the past year, the primary challenge for builders has been the governance gap, a hurdle so significant that Gartner reports 60% of GenAI proof-of-concepts were abandoned in 2024. The industry has signaled a definitive response: runtime enforcement is no…

  • Cyber Resilience Act (CRA)

    The Cyber Resilience Act (CRA), formally known as Regulation (EU) 2024/2847, is a comprehensive European Union regulation designed to improve the cybersecurity of products with digital elements. It establishes mandatory security requirements for manufacturers, importers, and distributors placing hardware and software products on the EU market, ensuring that cybersecurity is integrated throughout the entire product…

  • MiCA (Markets in Crypto-Assets)

    MiCA (Markets in Crypto-Assets) is the European Union’s comprehensive regulatory framework (officially Regulation (EU) 2023/1114) designed to govern the issuance, trading, and custody of crypto-assets. It establishes a unified set of rules across all EU member states to ensure market integrity, protect consumers, and provide legal certainty for businesses operating in the digital asset space.

  • The End of the Authentication Gap: Microsoft’s SSPR Enforcement

    As of September 7, 2026, Microsoft Entra ID has terminated the use of unregistered directory contact data for self-service password reset (SSPR). This SSPR retirement means mobile numbers, business phones, and secondary emails not explicitly registered as authentication methods no longer function for verification. Users relying on these legacy fields are now locked out of…

  • Authentication Gap

    To understand the authentication gap, it is helpful to look at where it lives. It is not a problem with the AI model itself, such as prompt injection (where a user manipulates the AI’s input to force unintended behavior) or data poisoning (where malicious data is introduced during the training phase). Instead, the authentication gap…

  • The 36-Day Zero-Day: How Authentication Failures Are Breaking Enterprise Management Planes

    In January 2026, Interlock ransomware exploited a zero-day in Cisco’s Secure Firewall Management Center for 36 days before anyone outside the attack chain knew it existed. Amazon’s MadPot honeypot network discovered the campaign only because the attackers misconfigured a staging server, exposing their complete operational toolkit – custom dual-language remote access trojans, memory-resident webshells, and…