What's a "novel" or "one-off" exploit? I don't see the realistic dividing line between "NOBUS" exploits that NSA could realistically believe it has a proprietary grasp on and the kinds of exploits that get deployed at Pwn2Own.

Configuration Errors are an example of "one-off" exploits. Things which are specific to a environment, rather then a code base.

