1. You're not subjecting HN readers to a site under the control of a malicious party who may have done more than just deface it. Even if you verify that you only receive plain boring text with no scripts, iframes, plugins, etc. it's impossible to verify that someone else won't get served different content. For example, malware that only gets served to people in Israel.
2. Once the compromised site is restored, people visiting the link won't see what happened. When you link to a third-party article, that article will persist even after the hack is long since gone.
3. Linking to a security research company will probably give better insight into the technical details how the attack happened, gratifying our intellectual curiosity, instead of just being a dumbed-down piece from some mass-market tech blog.