More

    CISA reveals warning on Asus software flaw, here’s what you need to do to stay safe



    • CISA added a critical Asus Live Update supply‑chain compromise (CVE‑2025‑59374) to KEV, tied to tampered installers distributed before 2021
    • The flaw stems from the 2018–2019 incident, where attackers implanted malicious code on Asus update servers
    • Federal agencies must remediate by January 7, and security firms urge private organizations to follow suit

    The US Cybersecurity and Infrastructure Security Agency (CISA) recently added a new critical vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, meaning it has seen it being abused in the wild.

    The vulnerability plagues Asus Live Update, a utility tool that comes preinstalled on many Asus laptops and desktops. It checks Asus servers for updates, and installs them automatically, including BIOS files, firmware, drivers, and more.


    https://cdn.mos.cms.futurecdn.net/VsnoQAEmxjEvebB3dyY9Pj-2560-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img