I have read about LoD/MoD, 8lGm etc..it seemed that low hanging fruit was probably the reasoning right? I mean, there were probably so many systems you could access through stupid bugs, that delving deep into SO wasn't necessary?
The vulnerability research community in 1995 was very close-knit (not tiny, but you could fit them in a hotel banquet hall for Summercon), and they worked pretty quickly to educate each other about the attack.