A recent development involving Poison Ivy (PI) remote administration tool (RAT) brought the debate back to life. The idea of finding vulnerabilities in tools used by attackers is not new. But I think it’s important to weigh the pros and cons of this disclosure of vulnerabilities in attacker tools. Intruders already know about the vulnerabilities anyway. By publicizing the vulnerabilities, it tips the intruders to defend their infrastructure by patching. Good guys now can put them to work attacking intruder infrastructure for “active defense” and “research” purposes.”]
Source: https://taosecurity.blogspot.com/2012/06/more-disclosure-of-vulnerabilities-in.html