A vendor update for the parking-meter backend includes a trojanized installer. What is the attack vector?
Select an answer to reveal the explanation.
Short Explanation
The city did the responsible thing and installed the vendor's own updater—and the updater was the payload. That is a software supply-chain vector, not a random PDF click. Trust in the parking-meter publisher was the path in.
Full Explanation
A trojanized installer delivered through a legitimate parking-meter vendor update is a software supply-chain vector. User-clicked PDFs, VPN password sprays, and USB drops are separate delivery methods. The trusted update path is what introduced the installer.