This is the very same concern cyber-security researchers face every time they notice a vulnerability. Do they publish their work openly and potentially leave all those using the service vulnerable to attack?
Yes, for a combination of two reasons:
1) They have obvious incentives to publish their results.
2) The more we know about vulnerabilities, the better we are at combatting ourselves against it.
That second reason is why we are (overall) better off from acknowledging possible threats to our existence. In your example, the more open the study of super-pandemics is, the more open the study of combatting against super-pandemics is. The more we are aware of a threat, the better informed we are to prevent it.
Yes, in your example, the threat could be highly dangerous and imminent. However, if only one individual was capable of creating a super-pandemic, the number of people who could potentially help stop it is drastically reduced. Rather than a free distribution of results which arms our society completely with the ability of preventing it.