I'm not an american, but I'm a spare-time security researcher, hoping to make a career out of this in the future. The last few cases reported here on HN give me the impression that if you stumble upon a vulnerability (which, by the looks of it, seems similar to the one involved in the AT&T case), it's best to keep it to yourself. You have nothing to win by reporting it, and possibly a lot to lose if you do.