Any code executing in privileged mode can bypass security, and is therefore inherently part of a system's trusted computing base (TCB). (Linux is a monolithic kernel running in ring 0)
Most companies are not Linux contributors, they are trusting the kernel developers to write bug free, secure code.
Minimizing the TCB and opting for an auditable open source TCB are really useful concepts in security.
But the cause of these breaches is much more trivial than what you are worrying about: these companies are basically installing whichever piece of software can decrease their costs without thinking about what they’re doing.