Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

McAfee patches flaw that turned protected systems into spam relays

Add as a preferred source on Google
McAfee SaaS Total Protection
Image used with permission by copyright holder

Security software is an everyday necessity for most people, especially Windows users, businesses, and enterprises. But one of the ironies of security software is that, once in a while, it turns out to be the source of security problems all by itself. The latest instance involves McAfee’s SaaS Total Protection suite, a cloud-based solution designed to provide comprehensive email and and Web filtering along with centralized security management for businesses and organizations. However, McAfee has just had to issue an update to the service to block a flaw that could let attackers execute code on protected machines, and to fix another problem that could potentially enable attackers to turn protected systems into spam relays.

“Two issues in SaaS for Total Protection have arisen in the past few days,” wrote McAfee’s David Marcus in the company’s blog. “In the first, an attacker might misuse an ActiveX control to execute code. The second involves a misuse of our ‘rumor’ technology to allow an attacker to use an affected machine as an ‘open relay,’ which could be used to send spam.”

Recommended Videos

McAfee says the ActiveX control issue, while new, is similar to a problem the company patched back in August 2011: As long as customers have applied that update, they aren’t vulnerable to the new problem. McAfee has begun rolling out an update for the spam relaying issue, and customers should receive the update soon if they haven’t already.

The Saas Total Protection suite’s “rumor” technology enables protected computers to communicate updates with each other in a fashion like peer-to-peer networking. The idea is to distribute updates automatically in-house on local networks rather than forcing every protected system to grab new updates from McAfee, potentially straining an organization’s Internet connectivity. According to reports, the service installs itself even if users don’t specifically ask for it, and while it can be shut down using Windows’ built-in administrative tools it gets restarted whenever McAfee delivers a software update.

Although the spamming vulnerability never put data on protected machines at any risk, attackers were able to use the rumor service to essentially bounce email messages off the protected systems, making it appear to the rest of the Internet that the McAfee-protected computers were the origin of the spam, rather than the attackers themselves. As a result, some McAfee users were mysteriously finding their machines and networks blocked by spam filters — in one case, apparently by McAfee’s own antispam technology within the organization.

McAfee was acquired by Intel in 2010.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Google Earth’s AI misadventure lasted only a day. It was a tale of dangerous ignorance.
Nuclear reactors, tanks, and historical destruction on a life-like satellite map? Yeah, that's bad.
Nano Banana AI image generator representation.

Technology behemoths are clearly not reading the room, or they are just moving faster than they should when it comes to AI deployment. Google has already stuffed its Gemini AI in every corner of its software stack, from Android to daily productivity tools like Gmail that are used by hundreds of millions of users every day. AI is everywhere. Not all of it is bad, mind you. But in a few places, it just feels forced.

In its latest AI-fication experiment, the company targeted Google Earth. The idea was to let the audience use its Nano Banana 2 AI image generator and make images that can be placed on the map view. On paper, it's a cool idea. What would the Colosseum of Rome look like in your urban neighborhood? Yeah, fun stuff like that.

Read more
AMD is apparently gearing up to raise GPU prices right after Nvidia’s steep hike
AMD has reportedly told AIB partners about a price hike that goes into effect in. August.
AMD RX 7800

AMD is next in line to raise the asking price of its Radeon GPUs, merely days after the news of a similar hike coming for Nvidia graphics cards started making waves. As per ChannelGate on Weibo (h/t VideoCardz), AMD has informed its board partners that the price of GPU and memory bundles will go up by at least 10% in August.

Is a similar price hike coming for standalone graphics cards? I won't be surprised if that happens. The situation is so bad that AMD is planning to bring back graphics cards with 4GB of onboard memory. AMD just introduced the RX 9050 GPU, which costs $279. Notably, it's just $20 less than the RX 9060 XT that offers double the graphics memory.

Read more
Microsoft will make Windows work well with just 8GB RAM. We desperately need it
The dream of a reliable and affordable Windows laptop hinges on the next milestone at Microsoft.
Surface laptop on wooden table

The year 2026 has marked a huge course correction for Microsoft after years of frustrating users with plenty of confusing processes, unoptimized UI elements, and just the generous bloatware that can bring any Windows system to a crawl. Microsoft has finally shifted into a new phase. From fixing the right-click behavior to speeding up the Search system, the company has fixed plenty of papercuts.

The next major milestone is making Windows 11 run smoothly on Windows PCs with just 8GB of RAM. That directly means entry-level and budget laptops will at least get the basics right, even if that means sacrificing the on-device AI bells and whistles. Let's face it. The increasingly AI-first approach to computing on a Windows 11 machine is a little too taxing on the hardware at hand.

Read more