Yes I agree, up until last year, core was an attack vector that had not yet been explored.
My reasoning, simply when I first started running a node. I went straight to Bitcoincore.org and downloaded the latest version. This can no longer be the default action of a new node runner. Instead they must think critically about their values and what they would like to support