I still can't believe more people complain about this being publicly disclosed than this being possible in the first place. No one is obligated to know the procedures on InfoSec 0-days and follow those steps.
I wouldn't bash the guy. Someone already let him know about his technical faux pas in a professional manner on his twitter. My guess is he found this vulnerability on accident, freaked out, and tweeted about it. Probably has limited infosec experience.
So he's either not reading his replies or he's being deliberately irresponsible. My guess, based on his profile and online behavior, is that he's trying to ride the coattails of getting some exposure online.