I mean it probably does that on Windows since it would be annoying to remember to update the browser manually but on every Linux distro I've ever used updates have been handled by the package manager
Depends on what you mean. If you mean using Tor to connect to HTTP sites/any other cleartext protocol is insecure, then you're right, the exit node can see where you're connecting to and the traffic being sent. If you mean using Tor to connect to HTTPS/any kind of encrypted protocol, then in theory your traffic should be safe, unless the exit node has a quantum computer handy to decrypt it.
Of course, using a Tor hidden service will always be more secure since there's no exit node involved.
I don't remember specifically what they did to make them dislike them tbh, I just remember Moonchild Productions being rude to users on their forums. I might have completely misremembered though