Nice. Still should have responded to them faster. Someone at Apple just dropped the ball when they got the report.
I don't think it is any specific "someone." I think Apple's policies/procedures itself are more at fault. The fact that there's no way clear route to submitting security issues if you aren't a registered developer is problematic.
I've worked with folks who field security reports full time... you gotta have someone who can work with people and respond. It helps buy time while you fix things... / good PR.