Who owns software vulnerabilities? The hacker or the company who owns the code?