logo

CISA flags ASUS Live Update CVE, but the attack is years old

ID: 3360124b-94ab-5aae-aca9-4f231ced1b80

STIX ID: report--3360124b-94ab-5aae-aca9-4f231ced1b80

Feed Name: Bleeping Computer

Threat Score
20/100

Date Published: 2025-12-22

Date Updated: 2026-04-20

Author: Ax Sharma

...
...

The report clarifies that CVE-2025-59374 documents a historical 2018–2019 'ShadowHammer' supply-chain compromise of the ASUS Live Update utility and is a retrospective classification added to CISA's KEV catalog; the affected utility reached end-of-support, there is no evidence in the report of new or ongoing exploitation, and the guidance is to ensure systems run the latest patched (or removed) versions while not treating the KEV entry as an urgent active threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.