Was it a closed experiment or did they get it out in the community?
I would think Linux would welcome an attack that exposed a vulnerability.
I’ve seen the patches that fixed the bugs.
The commit logs did not indicate whether the engineers who found and fixed the bugs knew they were of hostile origin.
The originators should never be allowed near a software development effort.
In fact, they should be permanently barred from any occupation that requires even a miniscule of trust.