From the Twitter advisory [1]: >>> To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it's already being read by attackers and defenders alike. Kinda turns the “many eyes” principle of OSS on its head,…
More people would have been harmed had the bug been in production longer.
One unfortunate aspect is that responsible disclosure would have only saved some people, a responsible disclosure would have lead to a notice to migrate seeds and bad actors would have immediately realized seed generation was the root cause and would have swept many folks before they could even see the notice for themselves and get around to migrating.