Why would WebAssembly be any more prone to exploits than JavaScript?
Do people actually read docs any longer? https://github.com/WebAssembly/ has some, my blog covered the 1VM requirement. There won't be a new "sandbox". JS and wasm interoperate over shared objects.
No, not really. People read headlines and make pithy middlebrow comments. Though I also don't think that's a new phenomenon...