Tavis Ormandy, a member of Google’s Project Zero initiative, recently discovered a series of vulnerabilities in Symantec’s security products. The vulnerabilities are far-reaching and can’t all be patched with automatic updates. Security software typically runs at a higher privilege level so it can inspect data going to and from other applications. Third-party software in general to be rife with vulnerabilities, he says, “You can’t leave in the hands of security vendors, not even security vendors””]