A security engineer discovers a zero-day vulnerability in a client's production system during a penetration test. The client's contract specifies findings must be reported within 30 days. What is the MOST ethical course of action?
-
A
Wait 30 days as specified in the contract
-
B
Report the vulnerability to the client immediately due to its severity
-
C
Publish the vulnerability publicly to pressure the client
-
D
Exploit the vulnerability further to document its full impact