My security/hacking background taught me that the security world progresses by disclosing vulnerabilities after they’ve been patched. I’ve encountered many cases where businesses would prioritize software updates based on the severity of publicized vulnerabilities. I’ve tried communicating that an advisory does not bear a company name, but they hold on to internal policies like a tick on a forehead.
The security of modern companies is build on the shared knowledge of security researchers. I’m physically appalled by the though that I’m helping a company exercise leach-like behavior, in which knowledge is only taken but none is shared. I would like to know how common this practice is, and what you consider to be an appropriate level of aggression against it, if any.