These statements always feel a bit circular to me. Sufficiently bad for what? Sufficiently bad to be indistinguishable from a cyberattack. So, "a software update bad enough to look like a cyberattack looks like a cyberattack". Well, yes.
E.g. supply chain attacks have become a hot topic in the last few years. This event suggests that your threat model for supply chain attacks should include catastrophic vendor cockups.