upvote
Agreed. I suppose they'd have slightly less credibility by saying "we hacked <unnamed company>" but it strikes me as far classier than naming & shaming.
reply
I'm not sure this is "naming and shaming" because I don't seen an intent to shame. They disclosed the vulnerability privately, waited months for patches, and were commended by the organization with the vulnerabilities.

There's no shame here, this was a mistake, probably made by a human, and ultimately corrected. Nobody seems upset by the outcome!

reply
shaming people for bad security practices is probably net good, whether we like it or not
reply
There is a big difference between "bad security practices" and "someone made a mistake 2.5 years ago"
reply