I don't understand why they didn't first contact the website owners. Isn't this exactly what the WHOIS technical contact is for?
More to the point: has a widespread public vulnerability ever before been released alongside a list of everyone who is vulnerable to it? I can't recall such a thing ever happening.
http://web.archive.org/web/20140411064356/https://zmap.io/he...
This sort of proves my point from another comment: they stopped updating the list shorting after it was posted, and so all of these domains are forever stuck on the shame list.
Viewing domains from the Alexa top 1M list so many times today also makes it very clear that it is total crap.