Hacker News new | ask | show | jobs
by _alternator_ 33 days ago
The key here is "high confidence" and "likely". For threat intelligence research, these words usually map to a probability estimate. In this case, "likely" would mean 55-80% probability [0].

The fact that they are holding some information back doesn't really strike me as unreasonable. The bug has yet to be released, so they should not provide identifying details. Let's see what happens with the CVE.

[0] https://www.cisecurity.org/ms-isac/services/words-of-estimat...