(re-)mount home [and other?] with noexec (and nosuid [among other useful mount options]) for better security?

related, follow-up tasks: