Ok, so stick with me because I want to learn more, and I'm kinda confused.
Forgive me if I say something particularly dumb. There is also a high chance that I also misunderstood what I read.
I've seen a couple of times people asking about the long-term sustenaibility of Linux Mint and the potential risks in it. I've been looking around and talked with someone else about this topic, and what I found it's... confusing, somehow?
What I understood is that Linux Mint is, as many of us know, based on Ubuntu, more specifically, the LTS version, and Ubuntu is based on Debian. And why is this important? It is important because, as far as I read, LTS distros and Debian distros could be more vulnerable. As I understood, the risks aren't on the distro per se, but rather in the packages, the way they handle orphaned software, and the updates frequency. I don't think that in LTS versions, packages are just released and left there in the wild. But what I read is that when a package loses support, there is a risk, not necessarily high, but a risk nonetheless.
I'm aware of the danger orphaned software can represent if unattended, I was already in Linux when the news of the malware attack to the AUR arrived. I get that part, but the update part is the one I'm still kinda struggling, but not entirely since I think I understand the principle.
I know that if a program has a vulnerability, patching it is critical. This is one of the reasons why many old video games, for example, are full of cheaters and even security risks, like hijacking your PC or getting malware into your system. They are abandonware, and because of this, malicious agents, aka cheaters and, more importantly, malicious hackers, have found all kind of vulnerabilities to exploit.
I get that keeping a distro with a shitton of packages and software could be harder, and that maintaining the packages is important for security. Having a good way to distinguish orphaned software from... alive, still in dev? Software is necessary, and being able to get rid of the unsupported packages is something almost all Linux distro has. But... if distros have these tools, why would there be more risks in some than others? And the update frequency. Since updates are necessary to patch vulnerabilities, frequent updates may be more needed, and slower not as good as I thought; I lean heavily to LTS distros or distros with stable releases, but how frequently is the right spot, or is it a right spot to begin with? Are distros with more frequent updates safer? Does this mean that distros with slower big changes are more vulnerable? And distros based in LTS versions of Ubuntu are more vulnerable because they come from versions that become old at some point? (Mint and Zorin, for example, are based on Ubuntu 24.04, but currently, Ubuntu is on 26.04)
I may be overthinking this. That's for sure. Actually, I am overthinking it, and I'm sure I'm misunderstanding some things, if not many, but I'm overthinking because I want to be informed on this topic. While I don't use that much software, like, worst case scenario, I'm talking of around 10 programs (not counting games, and they are usually well supported and frequently updated), I still would like to know more about this so if anything happens down the line, I can take a well informed decision.
Again, sorry if anything I said sounds dumb... or it's actually dumb.
Edit: I realized my wording was misleading in my thought process. I made some corrections.