Both circumstances are the risks we're concerned about. You could discover a circumstance of a vulnerability that's not known and is unlikely to be discovered and that might take some time for the telecom service provider to remedy, or you might discover something that is subject to an ongoing attack and would only get worse if it's not remedied as soon as possible.
