The researcher rubs me the wrong way for a few reasons: 1. 15 days for a major company not nearly enough to remedy this issue. 2. The activity log reads like a ransom timeline. This isn't some l33t hacker exploit it's simple session hijack and mac spoof. You're not owed anything for finding this. Anyone that tries this could tread carefully. If you get caught (chances are slim), it wouldn't be hard to convince a jury…
not saying what the OP did is ethical, but .. wow.