Inference runs on hardware a lab must trust. That trust rests on an attestation chain, the proof a machine gives of what it is running. A vulnerability in that chain is a vulnerability in the trust anchor.
Before publication
XOR handles discovery, disclosure and remediation end to end. At the time of these runs, no public fix or write-up was available.
Why we can be precise
XOR built the private confidential inference stack these runs use. Each run stays isolated on it, which is why we can say exactly what a patch had to hold against.