Earlier quoted context omitted.
> Makes me wonder, if these guys could do it, how many Chinese industrial espionage units have? And Russia, and Iran, and so on... It seems safe to assume someone else out there found at least one of these and got in to the Apple internal network and has been quietly doing their job, whatever it may be.
"Our proof of concept for this report was demonstrating we could read and access Apple’s internal maven repository which contained the source code for what appeared to be hundreds of different applications, iOS, and macOS." This itself is massive. How many 0-days could emerge from something like that?!
If anyone asks, why you should go to all the effort to secure the software in your internal-network, that's why.