We see a lot of attacks aimed at Firewalls, antivirus etc. This one is aimed at Cisco email security devices, see the article on Threatpost for more detail.

One of the major risks associated with the implementation of security controls is that the control mechanism itself carries a significant degree of risk. For example, if you put a device in the heart of your email infrastructure you had better ensure that you haven’t just made it easier for attackers to block email by attacking that device.

The same rules apply to security devices as to any other component. Make sure they are patched, monitor for abuse, be able to survive without them, have a backout plan.


Peter Glock
Over 30 years of designing, building and managing telecoms and IT services. Primarily working with large enterprise and professional services businesses in Asia, North America, continental Europe and the UK. Information security professional, secret physics nerd.

