I wonder why open-e spends so much time in improving features like iscsi and on the other hand major security concers are not fixed.

For example I see the following problems:

important outdated samba (Samba 3.0.26a fixed a bunch of security problems...)

important outdated clamav
Code:
WARNING: Your ClamAV installation is OUTDATED!
WARNING: Current functionality level = 10, recommended = 21
minor outdated php (5.2 instead of 5.2.4)

Even if you place the storage system in a cooperate network a system should be secure against exploits (in case of samba) and new new viruses should be found by the virus scanner.