• Is running an up-to-date web browser (Firefox ESR).
• Has all important data backed up to cold storage regularly.
• Is behind a router. All incoming ports are closed, except one for ssh. I've looked through openssh's CVE list and there's nothing concerning.
• Is running local software which I consider trusted.
I was originally also planning to get a copy of Little Snitch, as an additional form of monitoring. I haven't actually done that yet, but I should.
Some possible attack scenarios I can imagine:
• There's a zero day in Firefox. My vulnerable OS does not offer the extra layers of protection that a newer one might.
• Someone exploits Spectre/Meltdown/etc via Javascript. My attacker is incredibly lucky, and the tiny portion of memory they retrieve just so happens to be the bit that contains something vital like Bitwarden's master password.
• Someone emails me a malicious image which isn't caught by Gmail (personal accounts) or Microsoft Exchange (work account), and it infects my machine upon being rendered by Apple Mail.
• A person I know/trust is tricked into sending me an infected document, likely a PDF or MS Office file. Even though I don't have Acrobat or Microsoft Office installed, the vulnerability is compatible with Preview and/or iWork '09.
None of these scenarios seem particularly likely. The key here is that I'm not important enough to get hit by a targeted attack, and frankly I don't think I would survive one on an up-to-date OS anyway. In exchange for this minor risk, using my computer makes me much happier right now than it did six months ago.