But not everything can be "fair game" when providing a service for free. Surely it wouldn't have been OK if they suddenly included a bitcoin miner or extracted credentials. They offered a free service, people trusted it, depended on it. Now, in my view, they have some responsibilty to their users.
Giving a notice in advance and releasing a final image that patched the CVE would've been reasonably responsible.
Giving a notice in advance and releasing a final image that patched the CVE would've been reasonably responsible.