There were no malicious code changes, rather malicious and deliberate misconfiguration of the software.
Regardless, I think configuration should be treated as code (use version control and reviews, write tests), since the damage you can do through misconfiguration is often as great as anything you can do with code.