What isn't being discussed is what an indictment this is of Artifactory.
Let's be real, it won't be simply replaced in millions of sites.
What it needs is some serious scrutiny.
What isn't being discussed is what an indictment this is of Artifactory.
Let's be real, it won't be simply replaced in millions of sites.
What it needs is some serious scrutiny.
I also agree that a big issue here is crappy software.
The discussion revolving AI+cyber always revolves around the assumption that all software is crappy, and to a certain degree that may be true, but we could also take our jobs seriously and write good software, and much of the risk would evaporate. The described Artifactory bugs should have been caught with testing.
If the biggest impact of LLMs on the industry is a pressure to create good software, I’ll be thrilled.
I would love than, and it might happen as a process of natural selection, but instead we will get automated AI patch generation and patch application, and agentic EDR and agentic SIEM. All the while generating vast amounts of new vibe coded trash.
If I had the money I would invest in clever segmentation firewalls and application gateways, something like tailscale but requiring explicit permission to establish connection from A to B, that facilitates introducing monitors that validate and log.