I had an old Xp-based laptop running as a file-and-print server. It was behind a router, so not even fully public. Nothing was even running on it besides SMB shares, VNC, and a media server.
Some kind of botnet must have hit it, because one day I got a bandwidth-consumption notice from my ISP and found that an SSH server and a torrent system had been installed.