THE article discusses the issue of "silent patches"—vulnerability fixes released without public disclosure. Such practices, intended to prevent attackers from exploiting vulnerabilities, actually risk leaving defenders, such as penetration testers and IT administrators, in the dark. Many security professionals do not reverse-engineer patched binaries, thus missing crucial information about vulnerabilities.
The author argues for timely disclosure, as silent patches create a dangerous information gap favoring attackers. An exception is made for specific cases like SaaS products where updates are automatic. The article also critiques Broadcom's recent approach to giving paying customers early access to CVE patches, potentially enabling well-resourced attackers while delaying crucial information to the wider open-source community.