Ugh, I hate hearing about crap like this. Unfortunately, the incentives at large, public, consumer-facing companies always drives this behavior.
I would have done the following:
1. Shut down my account. 2. Send the exploit to the company anonymously with a deadline to fix. 3. Upon deadline, post exploit and cc the company.
The inability to publish is a rub, but I think we need a cultural shift to drive back corporate idiocy and protect consumers.