Correct me if I'm wrong, but Twitter knew about this vulnerability back in January, and they either didn't check to see if it was exploited, or they didn't disclose that it was, or they didn't have enough observability/audit controls in place to see 5.4M requests for account data that used this vulnerability?
That seems like gross negligence to me no matter what the reason for that is, but I play in a much smaller pond and maybe I just don't understand that the cost to do things ethically at scale is always greater than cleanup.