Don't forget MS. Took German privacy regulators until recently, more than 3 years after the release of Windows 10, to notice that the thing is phoning encrypted data home even after disabling as much of that stuff as possible.
Their final conclusion is that using Windows 10, in a data privacy-compliant way, is only possible with a "rest risk" [0]. Too bad that by now Windows 10 is not just in wide use among businesses, but also the de facto government OS, most of these installations running default settings.
Same deal with Intel's ME: The German Federal Office for Information Security, a bit like the IT department for the government, rated Intel ME's risk as high early 2018 [1]. Yet no actual consequences besides that release, government systems still running Windows 10 on Intel platforms.
So while a lot of the threats are known and acknowledged, nobody seems to really act on these findings.
[0] https://www.heise.de/newsticker/meldung/Datenschutzkonferenz...
[1] https://www.bsi.bund.de/SharedDocs/Warnmeldungen/DE/CB/2018/...