At every IT company I ever worked or friends of me worked there were huge security holes. The common thinking of management is, though, that it's under control. Exposing these holes publicly results in getting fired or maybe even getting sued (because usually job contracts prohibit you from doing something that "harms" the company or its image). I don't think there is much that can be done about it. I certainly wouldn't risk my job, decrease the chance to get a job from other companies and knowing that for all that I could only free the world from one security bug, when million new ones are created daily.