They have no publicly posted security contact. I ended up paying for a month of Linkedin Premium to message their head of Trust and Safety, and was originally pointed at a HackerOne program that had a ToS link that 404ed (it's now marked as "Program not live"). I was finally given a non-public email address, and provided details. I received no feedback until I queried the status and was told it was fixed. In fact, they'd fixed the specific issue but not the general category of issues.