
- CISA added a critical Asus Live Update supply‑chain compromise (CVE‑2025‑59374) to KEV, tied to tampered installers distributed before 2021
- The flaw stems from the 2018–2019 incident, where attackers implanted malicious code on Asus update servers
- Federal agencies must remediate by January 7, and security firms urge private organizations to follow suit
The US Cybersecurity and Infrastructure Security Agency (CISA) recently added a new critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, meaning it has seen it being abused in the wild.