I sincerely hope Twitter would know better than to leave those vulnerabilities exposed on any Rails code they're still using. Also, that probably wouldn't count as a "sophisticated" attack in their book...
Attacks are always described as sophisticated in press releases. What do you expect them to say? We were asleep at the wheel and got owned by someone pointing Metasploit on our servers?