The Patch Waited Six Weeks on Half the Servers. The Attackers Waited Four Days.
Wiz says attackers exploited three JFrog Artifactory flaws between 15 August and 8 September, chaining two of them to turn an unauthenticated request into an administrator token. All three had patches. Six weeks after one fix shipped, 59 percent of organisations were still vulnerable. Exploitation of the most serious flaw began four days after it was disclosed.











