Microsoft for example has 30+ year old C/C++ code in Office applications that customers install on their machines. This is an attack vector. Adobe Acrobat is another well known attack vector. These products should be rewritten in a safer language, like Rust.
Roughly 70% of the security issues seen by Microsoft are memory safety issues. This means that if that software had been written in Rust, 70% of these security issues would most likely have been eliminated. See: https://msrc-blog.microsoft.com/2019/07/22/why-rust-for-safe...
These companies should be held accountable for not investing in securing their code, instead of brushing them under the carpet and pretending that breaches are simply law-and-order issues, or that we need more laws to solve the problem.