Well, that's the Micro$oft way. Keep it secret until you have a fix; meanwhile unsuspecting users are merrily surfin away entering personal data that may or may not be compromised.
Yes, they could, and probably will track down the black hat, but at least the word is out and people can take measures to protect themselves.