Recently an NSA exploit called "DoublePulsar" has been modified to work with Windows IoT devices. Typically this exploit was used as a backdoor chain with the Eternalblue exploit.
Recently an edit to it has allowed for it to this.
The importance of this is that common things that run this are devices like point of sale kiosks as well as ATMs.