A trusted software vendor’s update channel is compromised and a malicious build is pushed to municipal workstations that auto-install the update. Which vulnerability / attack theme does this primarily represent?
Select an answer to reveal the explanation.
Short Explanation
When the vendor’s "trusted" update is the malware dropper, you are in software supply-chain territory — the pipeline itself was poisoned. Guest Wi-Fi bridging and XSS are different stories. Verify update integrity and monitor what municipal endpoints actually install.
Full Explanation
Compromised software updates illustrate supply-chain vulnerabilities where a trusted provider delivers malicious code. Objective 2.3 addresses supply-chain and malicious-update concerns. Unsecure wireless, XSS, and default credentials are separate issues. Municipal IT should validate signatures, stage updates, and monitor for anomalous post-update behavior.