>That's why it's a good idea to block connections of all protocols into address ranges where an attacker might be able to host a service.

It's not a terrible idea, but it's pretty far down the list if things to do. It will stop mass scanners, but probably not any targeted attack unless you try REALLY hard (and then you have a chance of breaking your own infrastructure by accident doing this).

They should start with updating their ghostscript sometime over the last 10 years. Then maybe think about separating some parts of their infrastructure.

I mean, wow, that's really 2012 tech, looks like new owner d invested completely nothing since acquiring 4chan.