Discussion in #bitcoin-core-dev Freenode revolving around many users apparently having the RPC port listening on public IP addresses.
Unknown why, possibly copying random configurations.
esotericnonsense | if this is actually a problem, could there be a warning sign or something in the corner of the gui that says 'rpc is enabled, did you know?'? (maybe it already exists)
wumpus | esotericnonsense: I think that's a good suggestion, no that doesn't exist, feel free to make an issue!
I'm not sure of the scale of this and how problemy it is, but if mumblings I've heard about 3000+ nodes having publicly accessible RPC are true it seems unlikely to be a wilful configuration.