County GIS clients auto-update from a compromised publisher after an email announced the patch. Which named term fits the compromise of that trusted update path?
Select an answer to reveal the explanation.
Short Explanation
The email was just the hallway announcement; the poison was the publisher's auto-update. When a trusted GIS vendor is the delivery path, the named term is supply-chain attack—not phishing. Do not let the announcement mail steal the classification.
Full Explanation
Compromise of a trusted software publisher's auto-update channel is a supply-chain attack even if an email announced the patch. Phishing would be the mail itself harvesting credentials or dropping the payload; ransomware and DDoS name later or different behaviors. The defining fact is abuse of the vendor update path.