24 hours means they don't deserve to be called security researchers. They're exploit creators. Given the material effect this would have on AMD's stock, one might also reasonably speculate about their financial interests.
One difference between security researchers and "exploit creators", which is a term I think you just made up, is that exploit creators presumably release exploits.
Don't tell HD Moore or the Metapsloit team about this, though. They may cry themselves to sleep tonight.
Creation and release are two different things. They have created the exploits, or else AMD wouldn't be taking them seriously. They have also contributed more to the re-creation of those exploits by others than they have to security. So you can quibble over whether others use the exact jargon that you would have, but that doesn't change the underlying reality.
This. Especially with the disclaimer that others have noted:
> "we may have, either directly or indirectly, an economic interest in the performance of the securities of the companies whose products are the subject of our reports"