While it does violate a bunch of cultural moral norms ... there is absolutely an argument in there that overall, over time, it would produce a more positive outcome for users than a straight white hat approach.
Refuting or discussing the argument would be interesting; painting the suggestion as objectively wrong using emotive terms doesn't really move us forwards.
To argue the other side, I think it is wrong because you can't know that the good you do will outweigh the harm you do. But everything, even seemingly beneficial things, have both good and bad effects and morality seems to be the art of balancing them. However, if somehow you had knowledge that the long-term good far outweighed the short-term harm, it seems like it becomes the ethical thing to do. In real-life you don't usually get that kind of certainty though.
If it leads to a better outcome, does it matter that it's blackmail? It's the age old moral question of do the ends justify the means. Like most moral questions the correct answer is not yes or no but "it depends." The real loser here would be the company with the retarded security policy, and they deserve what they get. If they have a bug bounty program, then naturally the ethical thing is to report the bug through the correct channels. If they don't then their users are the ones silently paying the price. If you wanted to be squeaky clean you could simply refuse to accept the highest bid if it wasn't from the company. In that case I really see no moral downside.
It saddens me to see so many who feel this way.