I feel like the most useful thing to know for anyone still using Magento 1 is that they should probably immediately upgrade the codebase to openmage https://github.com/OpenMage/magento-lts because jfc, and then seriously consider if their life would be improved with moving to some cloud service that manages security for them.