But rpm's question is a difficult one to give a clear answer on as there is so many factors involved. If said company takes 2 weeks to fix, should they list before then or wait till the fix? We all heard stories of companies ignoring exploits when brought to their attention and then there's people like Microsoft that takes months before they do a fix.
My personal opinion is to engage impacted company, give them time to review and asses how long it will take to correct. Come to an agreement on when the story will be published. I would go as far and say publish when he emails go out about password resets. Coordinate the comms so the public is aware what happened and assist in affected company in communicating how to resolve the issue.
It's a impromptu partnership and everyone will be glad of the outcome.
And if a company doesn't want to play ball...feck them and watch them burn
:evil: