Sometimes it's an active issue and at the end of the day someone must implement something terrible (knowingly or not -- direct a junior engineer to do some complex task with the expectation they'll leave behind security vulnerabilities, just as good as getting someone to intentionally leave an issue). Ethical engineers can and probably should quit -- who knows how much a required, dull ethics course would influence that though?
Other times at the end of the day it's just lack of engineers doing something -- typically due to management not signing off/budgeting. Ethical management won't even necessarily help here, the incentives don't change. Some sort of stronger corporate liability for negligence is needed, probably, but the problem is not generally the engineers -- engineers, with an ethics course or not, are typically the only people who care about these sorts of things in the first place! What's the largest dip in stock price due to a password leak? How about shady government collusion? Have any groups of shareholders demanded more care to avoid such issues at any company?
I'll wrap up with a joke: "It should be noted that no ethically-trained software engineer would ever consent to write a "DestroyBaghdad" procedure. Basic professional ethics would instead require him to write a "DestroyCity" procedure, to which "Baghdad" could be given as a parameter." --Nathaniel Borenstein