Second, lack of interest in QAing a package does not make the security issue any less of a threat.
This is to me the real incentive for moving updates from testing to released after a timeout. Any non-security updates should remain in testing for those (like me) willing to forgo the QA.