There has been a lot of stories lately about the famous
Google Attack. It's now becoming known that the flaw used was in IE, was reported in September, and was going to be fixed in February.
It's always tricky for vendors to juggle security flaws, but there are always two very important things to keep in mind. The first being that if someone reported the flaw to you, it's not an internal only secret, people generally suck at keeping secrets. It's very likely they have or will tell someone else.
The second important thing is that it's probable someone else found it at the same time.There have been numerous documented instances thorough history, where an important discovery is made by multiple people at the same time. It's not uncommon for the same security flaw to be found by two different people. With six billion people on the planet, there is plenty of room for overlap.
The real lesson here is that if you know about a critical security flaw, don't sit on it, fix it ASAP, even if you
think you have plenty of time.