Counter counter point: SQL injections and buffer overflows now require nearly intentional effort to introduce into a codebase, whereas they used to be the default.
The question is: when we find a common class of vulnerability, what's the best way to deal with it?