Server companies that don't apply published security patches should be prosecuted.
Security patches are a good thing, but you can't patch the inherent insecurity of an ad network that gives obscure layers of affiliates scattered around the world the ability to pipe javascript into a page. I sympathize with publishers who are trying to find a new model, but cannibalizing your brand and your readers' security in pursuit of click fees is not going to be the thing that fixes their problems. It just makes more problems for everyone.