PuTTY in your hands: SSH client gets patched after RSA key exchange memory vuln spotted

basically operated by one volunteer in charge of a small team of volunteers

There are lots like that. OpenSSL being a case in point, where every large company on the planet uses it, but it's maintained by a small team of volunteers who have to beg for sponsorship crumbs from a few big companies (

Maybe the EU would like to fund things like that properly, instead just handing out a few bug bounties to FOSS reviewers?

