They sound incredibly laxed on security and the "we were days away from fixing it" could be complete bull. To Lucas, it probably sounds better to say they were close to fixing it instead of admitting they were unaware of these exploits.
I find the disclosure in the blog post great, but the conditions they had leading up to the hack very disappointing.
If they were aware of the exploits, they should have taken quicker action. They'll probably be focusing on security big time now... they have no other choice.