A bit off topic perhaps, but is it fair, as the article does, to call these hackers "white hat"? Especially Vupen which sells to the highest bidder(s), although selected, should be considered black hat, as they don't work with the intention of securing software, they even advertise on their site that they will sell the worst security holes for offensive use only.