OK i see, re-reading this with your top level post is "not all vulnerabilities are the type that could be bought by (insert state actor)", which makes sense (for some reason I thought you meant that they were buying the type of bugs that would end up getting reported to a BBP, but I just misread the original comment).
And yes the Saudis definitely bought software from NSO Group but it's also been used by plenty of other governments, including half the EU...
Comments
OK i see, re-reading this with your top level post is "not all vulnerabilities are the type that could be bought by (insert state actor)", which makes sense (for some reason I thought you meant that they were buying the type of bugs that would end up getting reported to a BBP, but I just misread the original comment).
And yes the Saudis definitely bought software from NSO Group but it's also been used by plenty of other governments, including half the EU...