Linux is very secure. The problem is linux is general purpose and that means it can do a lot of things. You don't need "non-linux" (and it would only help a little) - you need a set of sane defaults which eliminate attack vectors.
The key will likely be something like Android, that's based on the Linux kernel, but locks the vendors into some notion of a safe environment, and applies updates in a timely manner (the Linux kernel still has frequent critical security fixes.)
(Having vendors be able to articulate what the devices should be able to connect to or do, and having the OS/runtime enforce that would be a huge step forward.)
But Android itself is also insecure primarily due to fragmentation and end-of-lifeing, hence the feeling of hopelessness.