Pelican is wilfully missing the point...
It doesn't make any difference whether you manually or remotely update your bus/whatever, if you don't know exactly what the update is/does, and can verify it, you have no security - thus you need to trust the manufacturer because you are at their mercy.
So if there's reason to believe your supplier might maliciously 'update' your safety-critical device, you shouldn't have bought it in the first place, and you certainly shouldn't apply unchecked updates (though you may be too late of course)... not really rocket-science.
Hands up who trusts Chinese manufacturers, or more to the point, the Chinese government! Other countries are available.
Not that I trust our own or our allies' manufacturers or governments even in peace-time, but at least their software updates/cock-ups probably aren't malicious.