Yes. But does every minor release fix bugs AND security holes? If some only fix bugs, the equation "not newest = insecure" is wrong.
So for PHP's 5.6 line, only 5.6.4 is secure, since 5.6.4 is a security release.
I'm currently crunching numbers for other platforms. For example, Nginx's last security release (for 1.7) was 1.7.5, so 1.7.5 -> 1.7.9 are all considered security.
Note that this list refers to those versions as released, not as OS vendors may have patched them.
But don't take my word for it... http://php.net/ChangeLog-5.php
At least 90% of releases have a bugfix with an associated CVE vulnerability.