More like "you must be on the newest version of everything all the time, or you will get hacked".

Because security fixes don't get backported, when they could, and few are still doing separate security vs. feature updates.

Even Windows is doing it now with CUs, bundling feature & vulnerability patches together, then deprecating the last version. You don't have a choice anymore, it's "accept the features or else"