CISA reveals Asus software bug warning, here’s what to do to stay safe


  • CISA added a critical Asus Live Update supply chain compromise (CVE-2025-59374) to KEV linked to engineered installers distributed before 2021
  • The bug stems from the 2018-2019 incident where attackers implanted malicious code on Asus update servers
  • Federal agencies must remediate by Jan. 7, and security firms urge private organizations to follow suit

The US Cybersecurity and Infrastructure Security Agency (CISA) recently added a new critical vulnerability to its catalog of known exploited vulnerabilities (KEV), meaning it has seen it being exploited in the wild.

The vulnerability plagues Asus Live Update, a utility that comes pre-installed on many Asus laptops and desktops. It checks Asus servers for updates and installs them automatically, including BIOS files, firmware, drivers and more.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top