OK, so we're at cross purposes. It looks to me like (1) I misunderstood something you said but (2) it still (2a) doesn't make sense and (2b) is distinctly more than "I just said they don't care enough for security".
Specifically: you said "This is the way they advertise for their wordpress.com version obviously. Stick with us or you get compromised." So, my mistake: I interpreted "their wordpress.com version" as "the latest version" rather than "hosting your blog on wordpress.com". That was dumb of me; sorry.
On the other hand, even after fixing my brain in that respect, I still can't see any way to read that as just saying that "they don't care enough for security".
If in fact it's true that wordpress.com consistently gets updated immediately when a new version comes out that fixes a security problem, and that people hosting their own WordPress blogs tend to be sluggish about upgrading, then I don't see why one of the things they say when a compromise happens is "you'd be in much less danger on wordpress.com". Because, y'know, it's true. What would be improper would be if (1) they are deliberately putting out insecure code to make their hosted version more appealing, or (2) the only thing they say when a security problem comes up is "come and use our hosted version". #1 is what it still looks to me like you were saying, but seems immensely improbable, not least because I find it very hard to believe that their net gain in paying customers from an incident like this one is positive. #2 would be bad. indeed; is it true?