There's nothing newsworthy here, just some guy trying to make a name for himself by giving his so called vulnerability a flashy name and website.
Credentials are sent BEFORE prompting the user to accept a self signed cert. So it sounds like an attacker can harvest credentials on a rogue wifi by spoofing DNS and using a self-signed cert. I don't have an iOS device so I can't test.
This does not appear to be the case (Tested on an iOS 10.3.3 device and an iOS 11 device).
It's really difficult to tell that's what's happening in the midst of all the incorrect statements and conclusions even up to that point, and with the B section being even more absurd. It's quite possible that the reporting to vendors would also miss the legitimate vulnerability through the rest of the noise.