Usually, they will simply copy and paste a published exploit with their own payload. But, it looks like they are now reverse-engineering the patches themselves,"
http://www.eweek.com/article2/0,1895...06dtx1k0000599

geez.....clever little bastards...

At least they need the released patch first....gives us a little bit of a chance

MLF