I think everyone should update ASAP
Agreed. Centova Cast was using the most up-to-date version of OpenSSL prior to this disclosure so it was vulnerable along with everyone else. Everyone should update immediately.
not sure why they didn't post a notification of this here
I thought the front page of our web site was about as prominent as we could make it but... I suppose you can't please everyone.
Do we know whether Centova have issued new keys along with the fix?
That's not how public key cryptography works. If we shipped a preconfigured private key with Centova Cast, everyone would have it so it would be equivalent to no encryption at all. Every deployment of Centova Cast (just like every web site) uses its own unique key.
If you're worried about your own key you would need to either regenerate it per Rodrigo's instructions if it's self signed, or contact your SSL certificate issuer if it's a commercial cert.