Linux is, unfortunately just as vulnerable to cross-site scripting and other browser-based attacks. The browser is also the biggest vector for Windows, and Linux has no better immunity, unfortunately.
I would recommend using NoScript or eqiv. plugin for your browser.
In my opinion, Windows' biggest security flaw, is teaching users to install software via the browser. But for non-open-source software ecosystems, it's quite difficult to create a white-list of safe programs.
My second recommendation is to, as much as possible, only use software from your repository.
In regards to the other recommendations about firewalls, while definitely not bad advice, if you are behind a NAT router, and on a small, trusted LAN, I wouldn't worry too much about it personally.
I would recommend using NoScript or eqiv. plugin for your browser.
In my opinion, Windows' biggest security flaw, is teaching users to install software via the browser. But for non-open-source software ecosystems, it's quite difficult to create a white-list of safe programs.
My second recommendation is to, as much as possible, only use software from your repository.
In regards to the other recommendations about firewalls, while definitely not bad advice, if you are behind a NAT router, and on a small, trusted LAN, I wouldn't worry too much about it personally.