logo

CISA Adds ASUS Embedded Malicious Code Vulnerability to KEV List Following Active Exploitation

ID: ce2d2dc7-3c32-5216-8fb0-30b4bbd746ef

STIX ID: report--ce2d2dc7-3c32-5216-8fb0-30b4bbd746ef

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2025-12-18

Date Updated: 2026-04-21

Author: Abinaya

...
...

CISA added CVE-2025-59374 — a supply-chain compromise of ASUS Live Update that delivered builds with embedded malicious code — to its Known Exploited Vulnerabilities catalog; the modified updates can trigger unintended device actions and potentially deploy malware. Because affected Live Update clients may be EoL/EoS, CISA requires federal agencies to apply mitigations or discontinue use by January 7, 2026, and urges all organizations to review, patch, or remove impacted software.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.