> The routine update, it turns out, is no longer so routine Is there the rare case that we shouldn't update because the update could contain a malicious payload? If the update gets served over plaintext HTTP I would treat it as suspicious and may even block it from connecting at all. I run the risk of having outdated software, but that can be addressed by storing the software in a machine that's not connected to The…
You don't ever update your security “computers” from some third-party outsourcer. What you do is have your own people constantly probing their own systems for potential vulnerability and patching it themselves.
* jeez ..SolarWinds run their stuff on FTP and "active directory". It's got to be a joke.
* “computers” .. not allowed to use the 'W' word ;]