"we still don't know how." No one is stating the obvious: we would know more if we had the source code.
Reading the source code we cannot be sure that some vulnerable software was not updated quickly enough on some production system of theirs, or say anything about DNS poising etc.