This is often repeated but it’s just obviously not true. It’s much easier to figure out how to exploit a server if I have its source. If I don’t, I have to throw a bunch of stuff at the wall and hope something sticks.
If I’m in the situation where I have a binary of a server without the source, I have to pay the cost of using ghidra or IDA for a few hours or days (or weeks) to figure out how the software is structured before I can come up with an exploit. If I’m dealing with an open source target that’s a cost I don’t have to pay.