Hours after hackers posted public code designed to take advantage of the recently patched Microsoft vector markup language (VML) vulnerability, VeriSign iDefense security researchers discovered a private, in-the-wild exploit attacking the bug.