CISA flags ASUS Live Update CVE, but the attack is years old
ID: 3360124b-94ab-5aae-aca9-4f231ced1b80
STIX ID: report--3360124b-94ab-5aae-aca9-4f231ced1b80
Feed Name: Bleeping Computer
Threat Score
The report clarifies that CVE-2025-59374 documents a historical 2018–2019 'ShadowHammer' supply-chain compromise of the ASUS Live Update utility and is a retrospective classification added to CISA's KEV catalog; the affected utility reached end-of-support, there is no evidence in the report of new or ongoing exploitation, and the guidance is to ensure systems run the latest patched (or removed) versions while not treating the KEV entry as an urgent active threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
