pretty clear we need to go back to full disclosure. i know of some big vendors with bad holes that were actively exploited who never disclosed, just like the bad old days.

https://arstechnica.com/security/2024/03/hackers-exploited-windows-0-day-for-6-months-after-microsoft-knew-of-it/

Hackers exploited Windows 0-day for 6 months after Microsoft knew of it

Technically, Microsoft doesn't consider such bugs vulnerabilities. It patched it anyway.

Ars Technica