OK ...just to confuse the issue. I've just read on a computer forum that Microsoft are now offering e-mail notification about security issues.
See here. You do have to register for the service and the e-mails are digitally signed (of course all computer users understand about this!) by Microsoft.
This means it cannot now be stated that Microsoft do not send out e-mails about security risks. I think that once word gets around that Microsoft does send e-mails, the fake Microsoft e-mails could get mixed up with any genuine ones.
Maybe they should think again about doing this.