seems odd to me that they don't publicly disclose the vulnerabilities, but they do publicly disclose the software versions affected by their "weaponized exploits", thereby giving the heads up to whomever might be targeted to avoid using that newly compromised software.