Earlier quoted context omitted.
I cannot think of any other reason why the new blog post wouldn't have mentioned the obvious connection to the earlier issues that they had. They want to make it seem like ChatGPT invented this use case but they know that the sample code that ChatGTP learned from was mentioned in their previous blog post.
There's a vast chasm between "whoever wrote this article didn't think to link to a similar issue a year ago" and "the first incident was a malicious hoax".
What the comment suggested was that they're now bringing this up again to get attention (and links) since it's combined with ChatGPT. That's not "malicious", but it's also not exactly "wow, we just realized this happens".