There is security against that, you can limit access for thunderbolt devices to various parts of memory, same as you could with Firewire. Thunderbolt is not anymore insecure than Firewire for instance.
There is the ability to protect memory from malicious devices with IOMMU, but it is often disabled by default. My experience with DMA attacks via Firewire or Thunderbolt is that they work out of the box.