It's just one of many reasons why Microsoft alone shouldn't decide what operating systems can work on UEFI machines. If the future is UEFI, then we need an industry body like the W3C or something to work with OS vendors, not just Microsoft.
The idea that an industry body would be more secure than the security department of major software company is something I don't see a lot of evidence for. Apart from the root DNS servers I can't think of any.
There are plenty examples of companies keeping something secure. There aren't many of industry bodies.
I'd trust a bank (well, some banks) before I'd trust either the W3C or IETF with the keys to the universe.
I doubt there is a single large company that has not been hacked at some point. It's just most hacks don't get reported and most reported hacks don't make the news.
An alternative was producing some sort of overall Linux key. It turns out that this is also difficult, since it would mean finding an entity who was willing to take responsibility for managing signing or key distribution. That means having the ability to keep the root key absolutely secure and perform adequate validation of people asking for signing. That's expensive. Like millions of dollars expensive. It would also take a lot of time to set up, and that's not really time we had. And, finally, nobody was jumping at the opportunity to volunteer. So no generic Linux key.