Isn't this somewhat unprecedented: a major vendor announced their source base has been actively compromised by a malicious party?
If so, this is a potentially industry-changing event.
If so, this is a potentially industry-changing event.
Whereas the NYT story is not a statement from a vendor.
We all interpret that as a hacker having placed a backdoor there, just as we interpret the Operation Aurora announcement as the Chinese government placing a backdoor in GMail and the NYTimes article as the NSA placing a backdoor in Huawei routers. We are probably not wrong in this assumption. But the same CYA deniability is in all three.
That would make it unprecedented, by your own description.