
How a forgotten node can put Oracle Java back in production
Azul has launched an AI assistant that answers plain-language questions about live Java runtime data, arguing that static estate reports go stale the day they are generated.
Enterprise Java vendor Azul announced its Azul Intelligence Cloud AI Assistant on Wednesday — a natural-language query interface that shows where security risk and licensing infringements hide in a live production Java estate.
Azul says it answers from live runtime data, replacing static reports that grow less accurate the moment they are generated.
Static reports go stale fast
Most IT and engineering teams still manage Java risk with static ITAM/SAM reports and code scanners that describe a single moment in time. Azul calls those reports accurate on the day they are generated and increasingly wrong afterwards, because JVMs keep changing underneath their scope.
"For years, enterprises built dashboards and reports to understand what runs in their Java estate, but by the time a report is reviewed, the risk it describes has often already changed," said Azul co-founder and CEO Scott Sellers. "Now that AI can weaponize a vulnerability in hours instead of weeks, it is a business risk — for security, for compliance and for licensing exposure in an audit."
The weaponization gap is closing
Azul cites AI models such as Anthropic's Mythos and OpenAI's Aardvark, which autonomously found real flaws, and an April 2026 Cloud Security Alliance paper: patching once took a median of 32 days, while in 2025 the median time to exploit had fallen to about five days.
The assistant puts an LLM-powered chat layer over two live Azul Intelligence Cloud records, JVM Inventory and Code Inventory, which track every JVM instance and the code that actually executes in production. Engineers can ask which JVMs lack the latest updates, where Oracle Java still runs, or what code is safe to remove.
In its FAQ, Azul notes that post-migration drift is common: a rollback, a forgotten node, a shadow deployment or an outdated script can quietly reintroduce an Oracle Java runtime.
A crowded market
Azul is not alone: Contrast Security sells JVM agents and bytecode instrumentation, Dynatrace offers Runtime Vulnerability Analytics, Fortify ships its Application Defender RASP agent, Thales-owned Imperva covers Java and .NET, and Datadog works through code-level tracing in its APM suite.
Andrew Krug, head of security advocacy at Datadog, told The New Stack that point-in-time scans are "not always representative" of the runtime environment. "Runtime context is absolutely critical for understanding real risk in production," he said. Datadog sees a rise in automated attacks on known flaws, especially in Java, because LLMs make it cheaper to weaponize new vulnerabilities.
Azul argues the maintenance overhead is real: unused and dead code is still tested and carried through every migration because no one can judge whether it is safe to remove. The larger the Java estate, the larger the exposure.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.