I am totally with you. If software is going to operate deadly weapons, it sure as hell better be secure.
But you are glossing over a LOT of detail here. The military doesn't work like Apple: they don't design, oversee, or directly control the construction of the hardware they use. And they shouldn't - the government is woefully inefficient at building products, that's what corporations are good at.
Here's the situation:
- The Air Force contracts General Atomics Aeronautical Systems to build UAVs. You can bet your ass the contract covers things like "protected from malware"
- General Atomics contracts out the different components of the UAV. No device worth $150M gets built by one company alone. The radar, the metal shell, the inside components, and each component of the software are all made by different companies.
- Each component is meticulously specified and rigorously tested. The makers of a component is contractually liable if they fuck up, giving them an incentive to do it slow & right. That's why it's so damn expensive.
- General Atomics puts the pieces together into the final product and delivers it to the Air Force after another round of rigorous testing.
- A team of guys in the Air Force are trained on operating the UAVs to deploy on missions.
=====================
So to say something like "Ugh, military, don't deploy UAVs if you can't keep it virus free!" is an oversimplification. These are extremely complex machines, with highly specialized embedded software, meant to deliver explodey things with extreme precision, while being operated from very far away. You can't just slap Norton on these things and call it a day.