The department had every intention of sharing the information at, I believe, Blackhat. A lot of research (especially security related research) is funded and approved by the government. Before they were able to give the talk at Blackhat, the government stopped them from doing so. Since the provided funding was from the government, they had to comply to avoid legal issues.
This is a matter of legal debate about the intentions and methods of the government, IMO. To reiterate I don't think it's fair to blame students/faculty/researchers for not breaking the law and agreements that allowed them to conduct the research in the first place.
As for what CMU has done to insure that this does not happen again... I don't know.