You do know the hash of the file part of the address, right? Any different file would by definition be a different address.
There could be an undiscovered bug in ipfs, but then that bug would be highlighted and fixed, and you could find a way to break the hashing algorithms, but then we'd have far bigger problems than an NFT being changed.
Also, the article you linked to lists no attacks on the blockchain, only theft of bitcoins using normal blockchain operations. That's like saying someone hacked the US dollar when doing a bank robbery.
Yep, this is good as in won't rail someone already developing or have developed something on Unity, but it has a lot of "and I would have gotten away with it if it wasn't for you meddlesome kids!" energy to it.