With the superfish fiasco first they insisted there wasn't any risk: “We have thoroughly investigated this technology and do not find any evidence to substantiate security concerns,” (https://www.techshout.com/lenovo-denies-accusations-that-its...)
Then once they were forced to admit the truth they released uninstall instructions that still left the systems vulnerable giving users a false sense of security. After security researchers started making headlines about their flawed removal instructions the company released updated instructions that actually removed the vulnerability they introduced. (https://www.theguardian.com/technology/2015/feb/20/lenovo-ap...)
Other security issues that never should have happened include multiple hardcoded passwords (https://www.bleepingcomputer.com/news/security/lenovos-finge... and https://www.pcworld.com/article/419336/lenovo-fixes-hard-cod...) and shipping machines with crapware that was designed to send data back to Lenovo but also introduced a vulnerability and worse was stored in UEFI so that even after reinstalling the OS your machine just reinfects itself. (https://www.pcworld.com/article/422988/lenovos-service-engin...)
see also: https://en.wikipedia.org/wiki/Lenovo#Security_and_privacy_in...
Who cares how good their compatibility with linux is if you can't trust the hardware its running on?