I don’t think it’s nonsense.
It’s important to be conscious of security, but that doesn’t mean automatically upgrading to everything all the time. There’s no way, that I know of, to be completely secure so I’d rather be conscious than a false feeling of safety.
I run Catalina 10.15.7 and I think I run it secure enough. Of course maybe I’m rooted and all sorts of bad stuff, but I don’t think so. Of course, maybe the most recent version has an unknown zero day (negative day?) and would also be rooted.
I think it’s naive to have a blanket rule like never run out of support software because sometimes we must. I run old devices that aren’t patchable or supported because they still have use (YouTube/Netflix) and I use them in an appropriate way, I think. I won’t conduct banking, but if someone breaches my Netflix account, I don’t care much. If it’s part of a botnet, I don’t care much. Of course it’s inconvenient and I don’t want to harm others, but then I also don’t want to keep buying dumb terminals for things and companies don’t seem to be changing their support timelines.
This isn’t even mentioning stuff that’s risky like continuing to run my smart lightbulbs even though Phillips stopped supporting them years ago.
I believe in calm technology and I’m not going to keep replacing stuff just because it has a non-zero risk.