What I don’t understand, however, is what more the team can do.
Here are a few ideas:
1) pull a feed of the latest Security Notice / Announcement over to the home page of modxcms.
2) Identify in the notice the ’level’ of the threat (high, medium, small)
3) Add more information regarding the threat and the solution in the notice
4) Add a prominent notice area for the foreign language forums. As it is, the announcements section is two levels deep and the notice does not get much visibility (I added a notice in the portuguese forum but was not sure if it was a support or an announcement topic).
Note that the Google result that you posted is to the MODx team’s response to the exploit, which in my mind is a good thing.
Arguable point of view, not sure if I share it. I would rather not see modx there at all (in the company of phpbb, joomla and other exploited visctims such as google), bad kitty. The results issue (if it is an issue) could have been avoided with a different post title for the warning (which could be another point, more descriptive titles, users who know what RFI Exploit are will most likely be more aware of the dangers, it is the users who do not know what that is that need to be made aware, and those may have overlooked the notice since they did not know what it meant and don’t use Reflect).
And on a final note, I think that this is a bit more serious a problem than the notices let on. Basically every copy of modx out there since Reflect was added to the package can have this problem. We know by the number of posts regarding register_globals that many hosts still insist on this setup. In many cases the end user (client) does not know that the developer disabled the warning since the server could not be changed (I have a client with the warning disabled, they were notified, but they have no idea what that means and have no control over this anyway, I obviously notified them and deleted the file and they were very happy I called).
This is by no means a criticism, I think that the team handles security issues very well and extremely quickly, kudos to the team and the community. I am off to sleep (knowing someone out there is watching over modx).