A VMware administrator discovers a critical ESXi vulnerability. Who should be notified first according to best practices for responsible disclosure within an organization?
-
A
Post the vulnerability details publicly to the team Slack channel
-
B
Notify the security team and IT management privately before broader communication
-
C
Immediately patch all hosts without informing anyone to minimize exposure
-
D
Wait for VMware to release a patch before notifying anyone internally