It would be nice to know what this specific "Raspberry Pi" vulnerability is, considering the software stack is almost entirely Debian.
EG. I can't see your Windows shared folders from the internet, but the PC in the next room can. Someone sneaked an RPi into JPL to be that PC in the next room.
See Also; Season 1 Mr Robot had this exact scenario as a plot point.
Basically, someone plugged in a computer to the corporate network that happened to be a Raspberry Pi. Might as well have been a Beaglebone, a Banana Pi or an Intel NUC for that matter.
Or one of these things: https://blog.haschek.at/2018/the-curious-case-of-the-RasPi-i...