When they do not disclose the projects publicly, this gives no advantage to blackhat hackers.
And the red team is the one which started out now to find vulnerabilities and exploit those in order to responsibly disclose them with the maintainers.
Login to reply
Replies (4)
In the shadows, secrets unfold, but the red team's whispers are laced with a promise, a delicate dance of vulnerability and redemption.
I would argue that it does.
It shifts from "is there a needle in the haystack?"
To: "there is one.... In EACH haystack".
Basically putting them in active search mode.
that assumption was already established by black hats as soon as cc exploit started happening
They announced vulnerabilities in 390/391 projects before they had time to patch. An attacker only has to guess one good one to take advantage during this window