That's a perfectly valid paragraph. In a decent environment, outbound internet access should be restricted to only the hosts / networks / ports that require it. Especially for server environments. Many servers running the backdoored Orion probably tried to beacon but failed for that reason. (And I'd assume the backdoor would probably first verify outbound internet access so that the failed beacon doesn't generate a firewall/ACL deny event that a security team might detect.)
Plus, the article is written to condense technical information into something that's as layman-friendly as possible. The specific malicious update has to be downloaded, and also installed, and also running on a server which can reach out to anything on the internet. Their point is that there are only going to be so many servers that both use this software and meet those conditions, and that's in part why the backdoor took so long to identify. This is maybe a little obvious to people with infosec knowledge, but definitely not obvious to their target audience.
The article timing is interesting, but I don't think a coincidence is that unlikely. If you read the whole article, it covers enough that I could see it taking months to make.
I don't think coordination with the government is that unlikely, either, or perhaps just a pragmatic editorial decision ("everyone knows sanctions are likely going to be placed sometime in the next few months, and maybe we should wait until then so we can include those details in the story"). Both of those scenarios are more likely than a coincidence, probably - but, either way, I think your post seems overly cynical in general.