CISA Adds ASUS Embedded Malicious Code Vulnerability to KEV List Following Active Exploitation
ID: ce2d2dc7-3c32-5216-8fb0-30b4bbd746ef
STIX ID: report--ce2d2dc7-3c32-5216-8fb0-30b4bbd746ef
Feed Name: cybersecurityNews.com
CISA added CVE-2025-59374 — a supply-chain compromise of ASUS Live Update that delivered builds with embedded malicious code — to its Known Exploited Vulnerabilities catalog; the modified updates can trigger unintended device actions and potentially deploy malware. Because affected Live Update clients may be EoL/EoS, CISA requires federal agencies to apply mitigations or discontinue use by January 7, 2026, and urges all organizations to review, patch, or remove impacted software.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
