It just doesn't mean much. They had something like 2 weeks worth of logs. And further, they never explicitly stated that the logs had enough context to show if it was being exploited. That is, are there any fields in the log files that could distinguish normal uri accesses from malicious ones?
I'm curious if that's all deliberately careful wording because they know, that they "don't know".