Earlier quoted context omitted.
Internal networks only accessible via VPN is considered an anti-pattern now in terms of security. It puts authorization firmly on the VPN. If the account with VPN access is compromised, then the attacker has full access to these sensitive systems. This hack probably underscores the importance of zero trust. Although if the system is compromised from within (like this hack is) then there is not much you can do.
I would be curious as to who is citing that using a vpn is some "anti-pattern", to what? Not protecting your network accessible assets? If you have the means, certainly use a corporate/smb/personal vpn. It is one layer in a multitude of layers you should be using to protect your network. Its not as if once you achieve vpn access you have no other authz gates to internal applications. Its a "great filter" to help narr…
You can safely ignore anyone that unironically uses "anti-pattern" or "dark-pattern".