> we can't say why you should apply it and how it will work, but you SHOULD apply it
Say, for instance, it was the kernel problem. They can submit a patch that says: "such and such was fixed, which caused privilege escalation". This does not contain the information about the actual intrusion into their systems, but is a genuine patch with a genuine explanation.
> And they STILL were compromised
It doesn't necessarily follow that a security bug was the root cause of this.