I wish reporters wouldn’t conflate two timelines.
On June 26, Citrix had no verifiable evidence that it was being exploited.
On July 9, Gossi had evidence that it had been exploited as far back as June 23.
Now, Citrix isn’t innocent in all this; they’ve had 3 days to put out an update stating there’s now evidence it was abused as early as June 23.
But that second paragraph in no way damns the first: an executive at Citrix had as little evidence as everyone else of the abuse 3 days after it had begun. That does indicate that telemetry to flag this sort of thing was lacking though — and Citrix knew about the issue itself long before; that’s just when it was made public and immediately abused.