A GCP professional discovers a zero-day vulnerability in a widely used open-source library. What is the ethical course of action?
-
A
Exploit it internally to gain competitive advantage
-
B
Ignore it since it is not their library to maintain
-
C
Follow responsible disclosure practices and notify the maintainers privately
-
D
Immediately post full exploit details publicly to maximize awareness