Of course, it would be better if there was an actually supported channel for sending this kind of information, but that's really not the fault of the people that end up finding this stuff and posting it internally (who are often not even related to the problem, posting more of a "hey, anyone know anyone who can help this guy?" message).
FWIW, the security disclosure form I posted will end up reaching a human, which is why I suggested doing that anyways.