But this is exactly the point (which I think is good). This whole thing is applicable if you produce software commercially, regardless if OSS or not
I read it as this:
In effect, if you make money of the software you destribute you are responsible to address security issues
I hope that this is a change for the better. Now everyone who piggy-backed on some OSS project so far has to either maintain a fork (-> more contributions) or provide incentive for the dev to fix it (money?)