I've yet to see a single case where a closed source software vendor accepted liability for data loss and / or security related issues.
Do you have a documented case where you can show that a closed source software vendor was forced to cough up at least a sizable part of the damages sued for ?
They all pretty much rule out stuff like that, and it would surprise me if such a case existed.
The situation is actually the reverse, because closed source gets leaked to the 'bad guys' only (by buying it off some employee with access) the chances of trouble there are a lot larger than with open source where there is a level playing field and the bad guys have just as much access as the good guys.
So, no, you can't sue anybody in the open source scene, but you can stay current. And you probably can sue some party in the closed source scene but the bigger question is what you'll do with the outcome of that suit.
Most likely the damages are limited to the price of the product by contract.