Here for example is an article where 2 months (yes, 8+ weeks) after some lines of code were shown to have an error in them (dubbed ???Heartbleed??? by a Microsoft-linked firm and then marketed like classic FUD) IDG is conveniently deducing that all of FOSS is not secure.