When do critical security updates hit PureOS?

Probably.

Yes. Usually I use this command:

sudo apt update && sudo apt upgrade -y