I’d blame modern day DevOps environments for this happening in the first place. Automated testing, poor timelines, rapid deployment and development. It’s a frigging rush-the-code-our-the-door factory where security is an afterthought handled by software engineers that might not know a lot about infrastructure or security. Horrible!
Hearing stories I'm pretty sure there is no modern day DevOps going on at Apple. That would at least flag several of these exploits.