I guess this is a reminder that writing secure C is actually really, really hard.
What is really hard is finding decent firmware engineers. Ones who care, and who can write secure code.
Even harder, finding a management chain that values security and that is willing to pay for it, and its continual upkeep (because security is a process, not a feature that you can complete and move on from).