CISA Reveals Warning About Asus Software Flaw, Here’s What You Need to Do to Stay Safe


  • CISA added a critical supply chain compromise Asus Live Update (CVE‑2025‑59374) to KEV, related to tampered installers distributed before 2021.
  • The flaw stems from the 2018-2019 incident, in which attackers planted malicious code on Asus update servers.
  • Federal agencies must remedy the situation by January 7, and security companies are urging private organizations to follow suit.

The US Cybersecurity and Infrastructure Security Agency (CISA) recently added a new critical vulnerability to its catalog of Known Exploited Vulnerabilities (KEVs), meaning it has seen abuse in the wild.

The vulnerability affects Asus Live Update, a utility tool that comes pre-installed on many Asus laptops and desktops. It checks Asus servers for updates and installs them automatically, including BIOS files, firmware, drivers, etc.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top