It would be reasonable to expect an increased interest in security architectures. Unfortunately security has not been a main focus of businesses - research, development and actual use of secure systems is mostly limited to academic, financial, defense and intelligence circles.
Current programming languages provide no effective means of applying the principle of least authority to third party dependencies.
Examples: restricting I/O of an imported library, in many cases down to pure computation, as well as accounting for and limiting their resource use.
People, take a look at (object) capability security: https://en.wikipedia.org/wiki/Capability-based_security
Systems implementing this let you handle permissions like other objects, transferring them by simply including them as a function parameter.
There is no ambient authority, meaning a string of a file path is not sufficient to open a file. The function needs to have access to a capability object, which combines authority (the right to do something, say read a file) with designation (the path to a specific file).
When you create a new process, it starts without any capabilities, in which case it is restricted to pure computation.
Unlike current systems, this passing of permissions allows you to reason about what your code actually can do, it effectively limits its behavior, it creates reliable boundaries, because the program can't just construct permissions out of thin air.