Disagree.
Apple's remote access feature, that you would make remotely accessible for obvious reasons, apparently had a critical authentication bug.
Apple did not ship a security patch for this, allowing the vulnerability to be exploited a week later despite "automatically install security updates" being on.
Yes, OP could have prevented this by putting an additional VPN authentication layer in front of the Mac's built-in remote access.
That doesn't excuse the mistakes on Apple's part.
> That doesn't excuse the mistakes on Apple's part.
Let's first establish that Apple definitely has a stake in this.
How long they can come up with a fix and then distribute them, that's a question. You can't expect any company to fix a vulnerability within 5min. Whether one week is too long or their delivery mechanism is good, I can't tell, and I don't think there is a standard in the entire industry.
That doesn't mean it's useful to write an article about "I didn't do my part BUT you are too slow". Even if Apple somehow fixes this within an hour of the disclosure and delivers the update, with the bad configuration, the machine is still vulnerable within that window. Does that change the nature of the narrative?