right now, every single remote code vuln that will lead to command injection or rce will make this #copyfail thing a very very big deal.
so all those qa servers and staging servers and test boxes you think nobody gives a shit about that are just flapping out there in the public, not being logged, not in the siem, not getting alerted on, not getting patched?
all those are gonna catch the "oops attackers overwrote sshd to steal creds" disease.
or cryptominers. or proxies.