It sounds like the idea that it's a donation is the part where we fundamentally disagree then. If you expose an unpatched exploit and the number of people using that exploit goes up because of your publication then you've contributed to worsening the security landscape for whoever the relevant user is. If an exploit is years old, or if there's some other relevant context, then sure exposing a vulnerability mainly means that the parent company doesn't have to pay for the research. But it's not a favor they asked you to perform and if you have a competing product with that company then the question becomes "Why aren't you publishing more about yourself?" since surely no one is in a better position to do security research on your products than yourself or a contractor you hired. It's basically PR motivated research and when there's also a lack of transparency it leads to easy speculation that maybe you're holding back research on yourself purposefully or even simply not publishing the more damning research you discover about your own products.