I work in this space and see these types of "hit articles" so often. These "security researchers/products" aren't doing anything more than spreading FUD and trying to sell their own products. Most of the FUD they spread is so widely misunderstood and positioned as if X thousands of machines/developers were "affected". The reality is much different. In the name of being a good security citizen, please just report thes…
What kinds of things do they do? Any idea how this slipped through? Do you know what the review process entails before a plugin is made available for download?