I feel as though both parties could have handled that better. Contacting a company about a security vulnerability via a tweet, there must be a better way about that. And the company's response seemed pretty disproportionate to me.
Maybe someone will learn something from this, or maybe not.