>> it doesn't seem likely something non-Linux-based will come along
The Mbed seems like ARM's answer to that, and it seems pretty good, works well of the mcu scale, and not that many vulnerabilities. But customers can't reliably choose it when buying, hence companies don't usually use it at scale. Simply put, IOT security is a "market for lemons".
What's needed is an mcu(or maybe a communication module), that comes with connectivity + security + updates from a major player - in a way that the product designers can't hurt security(no matter what mistake they make) - for example, by only offering a secure link to the company secure cloud server.
Than when users buy online, they can see that "this product's security is provided by Amazon/ARM/etc or maybe even a small third-party brand[1], with guaranteed updates for X years, or updates for $Y per year".
And it should be easy to verify that fact - for example, by using an app to scan the box or product label, and communicating with the product.
At this point, if this is done affordably, some users may decide to pay for that security, right ?
[1]It's possible to build good security and security brands online, like copperheadOs, for example.