Hacker News new | ask | show | jobs
by panarky 943 days ago
> The patch for the vulnerability was pushed to Github on July 5. Another actor exploited the vulnerability for a full two weeks beginning on July 11 before the official patch became available on July 25.

What's the point of a responsible disclosure embargo policy when the enterprise software developer alerts threat actors of the precise vuln three full weeks before they even begin to patch their customers' systems?