You should do due diligence on any advice you read on the internet if you are using it for something important, not just copy & paste.
These are not "security bugs" in the sense of 0-day remote code execution vulnerabilities.
These are simply configuration options which may increase security for certain use cases.
Setting up specific chroots , firewall rules and restrictions could well not make sense for many use cases.
Also stuff like fail2ban can lock you out of your server and requiring key based auth can be more complicated to get end users to configure if you are setting up for something like a shared hosting service.
Have you filed security bugs for all these ways in which Ubuntu is apparently insecure by default? What does the security team have to say about this?