Vulnerability research, in my experience, has been pretty collaborative and open - especially in the bug bounty space.
Just about every project has a bug bounty, but you'll be hard pressed to find any online discussion about works in progress towards a reportable bug.
Once you get over that hurdle, collaborating on targets is pretty common. Made $10k USD last month collaborating with someone in another country, in fact.