If it's my data/money getting stolen, I'd give no fucks about MSI getting a fine or whatever the usual reaction to these fuckups is. On the other hand, if I found an exploit and there wasn't a bounty available, I'd still report it. Betterment of the world and all that.
Getting your users computers infected and having to deal with bad buzz, prosecutions, loss of sales, would most likely wake them up.
Sending them a mail ? They don't care.