A utility billing API in the city’s cloud is breached after scanners find a known flaw in an outdated third-party library that patching tickets had delayed for months. Which attack path does this describe?
Select an answer to reveal the explanation.
Short Explanation
Old libraries with published holes are candy for attackers—especially when the change ticket sat in someone’s queue for months. The breach here is classic vulnerability exploitation tied to human delay, not sci-fi crypto or stolen racks. Patch cadence matters as much as fancy firewalls.
Full Explanation
Attackers routinely exploit known weaknesses in unpatched dependencies once CVE details and public exploits circulate. Delayed remediation on municipal application stacks creates a predictable window for remote compromise. Cloud+ security monitoring expects operators to connect outdated software and process lag to exploitation risk, independent of exotic physical or unrelated on-premises scenarios.