I'm literally not surprised by anything in this article. Joomla is a mess (my opinion, doesn't actually matter to my point), written in PHP so whenever a patch is released, you can see exactly what the exploit was. In fact, I'm surprised it's not less than 2 hours.
So obviously, "Patch now!" - although, that's not the prerogative of this site, it's to convince you to purchase their "website antivirus" -- which I still can't work out what it actually does, or where it sits.