I really don't know why I bother anymore, since Cisco never provided ANY useful answers on questions, but I still try it:
1. This bug indeed leads to a load of malicious attachments not passed to the file analysis, but sent to the end users. This is a severe issue - why was there no information by Cisco proactively to the customers?
2. why does it takes weeks or months to fix a bug that has consequences this severe?
3. file analysis is used to detect things that a classical AV (like ClamAV) can't detect. So, why is a classical AV (like ClamAV) even used to decide if a file is going to be uploaded to file analysis?
Answers would be much appreciated!