It's probably out of spite. At an OSS project I worked on previously they'd always hack into competing projects when they trashed the project's security.
If you live in a glass house, don't go around throwing stones.
That's 100% completely wrong. We've worked with Rails' security team in the past to coordinate releases fixing similar issues, and they've helped us out with discovering and analyzing issues of our own.
They're a great group of people and I've got nothing but good things to say about our work together.
Yet another reason why open source is fantastic: friendly competition can actually be friendly. It rocks.
Or if there's actually a history of web frameworks doing behind-the-scenes coordination and watching each other's backs... oh wait, that's not as good a gossip narrative. Never mind.