Its not
that gloom and doom.

There are vulnerabilities, but the risk is still fairly small. Defense in depth is your best defense. Running from a non-admin account can be one barrier, running a two-way firewall like Little Snitch can be another, using a hardware firewall another. Run
nessus scans of your machines every once in a while. It will tell you if you have something configured in an insecure way. These should protect from automated "casting a wide net" scans finding your machine as a good target. In the words of hikers, you don't have to outrun the bear, you only have to outrun the guy next to you. If the guy next to you has Windows you have a small head start. If it is unpatched Windows, the bear is already having lunch. Stay up to date on patches so the Windows guy doesn't pass you.
If someone is specifically targeting your computer, then your chances go way down, but I still don't think it is hopeless. Leave a decoy Windows machine on to feed the bear.