CISA Flags Critical ASUS Live Update Flaw Exploited in the Wild

CISA Adds Critical ASUS Live Update Vulnerability CVE-2025-59374 to Known Exploited Catalog, Urges Discontinuation by 2026

  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability affecting ASUS Live Update to its Known Exploited Vulnerabilities catalog.
  • The flaw, CVE-2025-59374, involves an embedded malicious code vulnerability caused by a supply chain compromise.
  • The issue originated from a 2018 attack known as Operation ShadowHammer targeting select devices via their MAC addresses.
  • ASUS has ended support for the Live Update client as of December 4, 2025, recommending users upgrade to version 3.6.8 or later.
  • CISA advised federal agencies to discontinue use of the tool by January 7, 2026, due to ongoing security risks.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included a critical vulnerability impacting ASUS Live Update software in its Known Exploited Vulnerabilities (KEV) catalog as of December 2025. This action was prompted by observed active exploitation of the flaw.

- Advertisement -

The vulnerability, tracked as CVE-2025-59374, received a CVSS score of 9.3 and involves malicious code embedded into the software through unauthorized changes made during a supply chain compromise. According to the CVE description, affected devices met specific targeting conditions and ran compromised versions of the Live Update client, which allowed attackers to cause the devices to perform unintended actions.

This vulnerability traces back to a supply chain attack uncovered in March 2019, when ASUS confirmed that an advanced persistent threat group had breached some of its servers. The incident, called Operation ShadowHammer by cybersecurity firm Kaspersky, took place between June and November 2018. The attackers embedded trojanized updates with a hard-coded list containing over 600 specific network adapter MAC addresses to target particular systems.

At that time, ASUS acknowledged the attack, stating, “A small number of devices have been implanted with malicious code through a sophisticated attack on our Live Update servers in an attempt to target a very small and specific user group.” The company resolved the issue by releasing Live Update version 3.6.8.

Recently, ASUS formally announced the end of support (EOS) for the Live Update client as of December 4, 2025, with the final version being 3.6.15. Following this, CISA urged federal agencies still using the software to discontinue it by January 7, 2026, due to unresolved security concerns.

- Advertisement -

ASUS stated on a support page that it is committed to software security and encouraged users to update the Live Update software to version 3.6.8 or later to address security risks. The company offers automatic, real-time updates through the Live Update application to protect devices from vulnerabilities.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Institutions Pour In: 2026 Poised to Ignite ETH Value Rise!!

Ethereum insiders say 2026 could trigger significant ETH value growth as institutions increase on-chain...

EU Debates Digital Euro Privacy, Holding Limits: Compromises

The EU Council has endorsed the European Central Bank design for a digital euro...

Iran Military Export Center Accepts Crypto Payments for Arms

Mindex is accepting cryptocurrency for sales of advanced weapons systems.Buyers can pay with crypto,...

BRICS Accelerates De-Dollarization: Unit, CBDCs, Payments…

India assumed the BRICS presidency and is steering a 2026 push to reduce reliance...

Tesla surges 89% in Norway; France, Sweden plunge 66/71% Dec

Tesla registrations in Norway jumped 89% in December to 5,679 vehicles.Tesla finished 2025 as...
- Advertisement -

Must Read

What Is a Sim Swap Hack?

You've likely heard the term 'sim-swap,' but do you really know what it means? It's a type of fraud that's rapidly increasing, where scammers...
Bitcoin (BTC) $ 90,560.00 3.04%
Ethereum (ETH) $ 3,138.75 5.34%
XRP (XRP) $ 1.98 6.18%
Bittensor (TAO) $ 244.56 8.67%
Polkadot (DOT) $ 2.06 8.03%
Cardano (ADA) $ 0.38922 11.41%
Chainlink (LINK) $ 13.32 7.64%
Hyperliquid (HYPE) $ 24.62 0.92%
Monero (XMR) $ 419.50 0.13%
Hedera (HBAR) $ 0.120253 8.70%
Toncoin (TON) $ 1.82 8.38%