"We’re not trying to get into an argument with the security guys. They’re dealing with theoretical concerns." - Peter Hortensius I'd say that someone having cracked out the password for the private key is a bit more than a 'theoretical' concern. This might be the most tone-deaf handling of a potential PR disaster so far this year.
You say you do due diligence to make sure the software you include is secure... yet you miss on such blatant vulnerabilities.
"Not doing enough" only scrapes the surface.