Attackers are hiding PHP scripts in EXIF headers of JPEG images to hack websites, just by uploading an image.
Source: Threadpost