Explainer
Everybody Audits the Package. Nobody Audits the Shelf It Sits On.
A flaw in JFrog Artifactory rated 9.8 lets an unauthenticated attacker on the network take administrative control under default configuration — minting admin tokens, forging credentials, reading the whole access topology. Disclosed on 28 August, observed being exploited in the wild by 1 September.
