Thanks for the post. I found this particularly funny:
The compromise was not the result of a software vulnerability, and as
we have previously stated, our investigation has revealed no such
vulnerabilities.
I also found it interesting that it appears they decided to conduct their own investigation. Does Fedora employ Incident Response and Forensics people?