When you don't update, you will eventually have software full of known security 
bugs. Known security bugs (if they aren't properly managed, like analyzing 
their impact and mitigating them) are arguably worse than unknown security bugs 
(ceteris paribus), because they are much cheaper to exploit.

The same does not apply to non-security bugs. The key difference is that 
security bugs are triggered on purpose, while other bugs are triggered 

It is questionable if old software with security patches (e.g. Debian stable, 
Firefox ESR) is better than fresh one or not. I see good arguments on both 
sides, so maybe it depends.

Vít Šesták 'v6ak'

