Earlier quoted context omitted.
The problem with security reports in general is security people are rampant self-promoters. (Linus once called them something worse.) Imagine you're a humble volunteer OSS developer. If a security researcher finds a bug in your code they're going to make up a cute name for it, start a website with a logo, Google is going to give them a million dollar bounty, they're going to go to Defcon and get a prize and I assume…
Except that the only people publicizing this bug were the people running the ffmpeg Twitter account. Without them it would have been one of thousands of vulnerabilities reported with no fanfare, no logos, and no conference talks. Doesn't really fit with your narrative of security researchers as shameless glory hounds, does it?
Note FFmpeg and cURL have already had maintainers quit from burnout from too much attention from security researchers.