Forescout: Your Zero Trust Program is Half-Scoped.

 ET
Online

Zero trust doesn’t fail. It gets scoped too small.

Many Zero Trust programs rest on a the basic assumption that if you verify the user, that’s zero trust. But Vedere Labs’ 2026H1 Threat Review documents attacks that bypass MFA entirely like ConsentFix phishing, SSO vishing, OAuth device-code abuse. When the attacker never has to break the identity, it’s not the control you thought it was.

We sit down with Dr. Chase Cunningham to challenge the assumptions the industry has stopped questioning and to make the case for what “universal” actually has to mean.