The vulnerability was found through the company’s bug bounty program, now in its tenth year.
http://www.wired.com/