I agree that this is a
terrible move, in theory. But in actual practice, I'm not convinced it will be so bad.
Because if you're not using that Yahoo account for e-mail anymore, then you're probably not using it as a sign-in or password recovery e-mail for your banking, Facebook, or anything else important -- because the whole point is, everything that's actually important to you, you're using your current e-mail address. After all, that's where important account notifications go, credit card receipts, bank statements, password resets, etc. -- things which are necessary for you to see.
Of course you'll likely have a bunch of accounts you forgot even existed on random sites you signed up for in the past, with your old Yahoo e-mail address. Most of them will be harmless -- who cares if someone gets access to some random sports forum you once posted on.
The biggest risk I can see is that 1) the new owner chooses to be malicious, 2) successfully locates a site that sends out password-recovery emails with the original passwords in plaintext, which the specific user has an account on, 3) knows the original user's current valid address, 4) tries the old password on the user's new address they use with banking/etc., and it works. But the risk of this would appear to be so small, that it's just lumped in with all the other kinds of "identity theft" weaknesses that already exist (guessing security questions, etc.).
(And then, there's scamming on whatever social networks or forums the old e-mail address had an account on. Although it seems like Facebook etc. is protecting against that? And it's not like spoofing e-mails/accounts is anything new.)
As long as Yahoo is giving significant heavy warning to the e-mail accounts themselves, and months' worth of time -- well if you never check your free e-mail account, it's not unreasonable to expect that it might be deactivated someday. Annoying, but not unreasonable. And if you use the same password for your Facebook, banking, etc. as you did for other random sites you signed up for years ago, then that's a security risk regardless of what Yahoo does.