Just the rumour of a bug is enough to find an exploit these days
Summary
The article argues that traditional OSS security embargoes no longer buy time against attackers who can cheaply assemble exploits from public hints. It proposes new mitigation directions, including private patch workflows, continuous public shipping, and protocol-layer protections, to reduce exploitation windows and improve defender remediation throughput.