I argue that they are definitely knowledgeable and capable of security. The nuance is they care about their own security, not the users'.
Case in point: Their MacOS installer abuses the pre-installation step to fake a System prompt to obtain root, very much like malware. Before you actually click install, it's already done [1].
In this case it was merely a shortcut to reduce the number of clicks to install, but it clearly betrays their disregard for user control & security.
[1] https://www.digitaltrends.com/computing/zoom-mac-one-click-i...
* SEO Bonus: I couldn't find this article on Google no matter what I queried for. But DuckDuckGo found it on my first attempt.
Guess abusing SEO to hide negative press is among their tactics as well.