The risk is limited to manually exposed APIs, and version 2. 4. 4 closes the standard public path.
Source: [CryptoSlate](https://cryptoslate.com/malicious-bots-are-actively-probing-exposed-bitcoin-payment-servers-to-steal-master-administrative-keys/)