One should be have been assuming since Windows 7 and automated online updates that the Microsoft key used to sign OS updates is in the hands of at least the NSA (and hence probably the Israeli equivalent) and they can push whatever they want to your computer as an OS update, bypassing all protections.
In fact the same applies to Linux updates of certain distros - if they're maintained by a company based in the US they can be forced by FISA courts to provide the signing keys to the US Government.
More in general, just go read about FISA courts and their secret court orders - companies based in the US or hosting things in the US can be secretly forced to just "give the keys of the Realm" to parts of the US Government.
Since things like the Patriot act one should be treating companies based in the US as just as untrustworthy as companies based in China.
(By the way, some other supposed Democratic countries have similar or worse systems - for example the equivalent of FISA courts in the UK have things like secret court sessions were the side which is not the State is not authorized to have a legal representation, see most of the evidence or even know the decision of the court).
Have people already forgot most of what came out in the Snowden Revelations?!