Yeah, that's the part that seemed odd to me as well, though someone knowledgeable in this area of law (at least in the better-settled offline case) could give some better info.
I believe it'd be okay, and probably actually happens, for a private security consultant to do threat assessments for a (non-criminal) client, e.g. prepare a report for DHS on the security of U.S. oil installations. But it seems like they'd be crossing a line if they posted a press release trumpeting a major vulnerability they discovered, mentioning by name which company and approximately where the vulnerability was located, but then refused to disclose it to the company in question.
I'm not sure how much it survives, but I believe there was traditionally even a common-law "duty to warn" if you were aware of significant risks to someone's person or property.