About the security content of Security Update 2018-001
support.apple.com
support.apple.com
https://security.googleblog.com/2014/07/announcing-project-z...
- SHAttered(?)
- Row hammer
- Cloudbleed
- Lastpass exploit
- Meltdown & Spectre
> This result is the product of a long term collaboration between the Cryptology Group at Centrum Wiskunde & Informatica (CWI) - the national research institute for mathematics and computer science in the Netherlands - and the Google Research Security, Privacy and Anti-abuse Group. [...]
People need some kind of pointer about _why_ they might want to read a security update statement.
Granted the original title should have included Tencent's name too.
Furthermore, Project Zero was involved in only one of the CVEs anyway then. Why not put the other credit in the title too? CVE-2018-4187: Zhiyang Zeng (@Wester) of Tencent Security Platform Department, Roman Mueller (@faker_)