Lets say I have like 10 very competent engineers on my payroll. Given the fact that artifactory exploit was basically figuring out a combination of auth headers and request data to send, how long do you think it would take them to write python scripts to try all combinations that leads to a zero day?
My main skepticism isn't even that, it comes from working in security. In general, if Im setting up publicly accessible service infrastructure, with security in mind there are 2 things Im absolutely going to implement in a firewall setup.
First is statistical traffic detection to check if we are being hit with too many failed requests from consistent endpoints, and heavily throttles that traffic based on fingerprinting.
Second is payload inspection to see if there is anything that looks like shell code in there, and automatically ban the ip.
Both of those are basically enough to prevent any number of agents (or team of 10 engineers) from essentially brute forcing a logic exploit.
So either HF team is incompetent, which given its prominence and buyout by Nvidia, I highly doubt it. Or something fishy is going on.