Sort:  

True, some can also be handle in silence, when the consumer doesn't get directly affected, but one the security is on the line and you are not sure that you can fix the issue, then you have to be transparent and inform of how the issue is being handle... this can damage the project tho, since people don't like being compromised... they should be grateful for being told the truth but ignorance is a bliss

You're right. Though saying something can damage the project it is important to let people know their security has been compromised. I now as a consumer I would appreciate that honesty