Earlier quoted context omitted.
Anyone with access to the private key can submit a problem report to the CA, they're obligated to revoke if the key is exposed to a non-subscriber. I have submitted a report - they are obligated to revoke within 24 hours.
Looks like they've failed to perform the revocation in time -- other users reported to Entrust >24h ago.
If other users reported it and they failed to act, that's a BR violation and they're required to provide an incident reports to the root programs via Mozilla's mechanisms.
If they don't, and you have evidence of those reports, you should provide them to the root programs via the mozilla.dev.security.policy mailing list/group. There's already a thread about this issue, though not claiming that EnTrust was notified.
(Based on timestamps, it's also possible they revoked in response to that thread).