Apple's remote access feature, that you would make remotely accessible for obvious reasons, apparently had a critical authentication bug.
Apple did not ship a security patch for this, allowing the vulnerability to be exploited a week later despite "automatically install security updates" being on.
Yes, OP could have prevented this by putting an additional VPN authentication layer in front of the Mac's built-in remote access.
That doesn't excuse the mistakes on Apple's part.