There have been security vulnerabilities found in every piece of networking/server software, Period. The trick is that on Windows, even Microsoft is often not notified of these for months after their discovery by the black hats, and it has been sometimes two years for a fix. You as a consumer may NEVER know about them.
And how, exactly, is this different to the situation with Linux? There is no guarantee that someone will report a vulnerability to the maintainers of, say, a Linux distro, any more than that someone will report one to Microsoft. And what Linux distribution or major infrastrucuture project still runs an open access security mailing list today, with guaranteed full and immediate disclosure of all reported vulnerabilities?
Ultimately, unless you personally are directly involved with the security and maintenance of every major Linux project you use, you're still trusting other people to be honest in their disclosure and prompt with fixing security issues.
the U.S. Army is “the” single largest install base for Red Hat Linux. Industrial Commercial Bank of China runs Linux at all 20,000 of its locations. The Chicago Mercantile Exchange employs an all-Linux computing infrastructure and has used it to process over a quadrillion dollars worth of financial transactions. No money in Linux malware? Pshaw.
Yes, because obviously the people who are responsible for systems processing a quadrillion dollars of financial transactions just throw a quick Debian CD in the drive to set it up. I don't suppose they're taking any extra steps to audit or secure their systems beyond what a typical home user running Windows for Facebook and gaming would do. Hell, you could probably just walk right into their data centre and remove a hard drive while no-one's looking, and then take it home to look through the files in your own time.
But no, Linux doesn't make you magically immune. It simply has a more mature and advanced security model, better tools for detecting and stopping intrusions, and the ability for a motivated firm to make any security modifications needed on their own schedule.
Leaving aside whether or not any of those things are necessarily true in 2012, about 99.37% of the Linux user base is also experienced enough not to fall for typical malware scams, but I don't suppose that makes any difference.