This is a really dumb take.
Having a security researcher you can spin up (and therefore an army of researcher you can spin up) is not a nothingburger.
That it hasn’t found a new class of vulnerabilities is little consolation if it can pump out vulnerabilities from known classes.
As for the second question, I think our default stance should be “yes” given the history of every other model advancement.