Asus Live Update is a technology platform tracked across 5 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed December 18, 2025; most recent activity December 22, 2025.
ASUS Live Update is ASUS's automated update utility for devices, drivers, and firmware. Recent cybersecurity reporting indicates its vulnerabilities have been actively exploited, leading to official warnings, CVE tracking, and advisories to remove the tool to mitigate risk on Windows endpoints.
Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…
The ASUS Live Update vulnerability, identified as CVE-2025-59374, relates to a historic supply-chain attack affecting an End-of-Life software product. Recent media coverage has inaccurately suggested that this…
CISA has included a new vulnerability affecting ASUS Live Update in its Known Exploited Vulnerabilities catalog. The flaw, identified as CVE-2025-59374, poses an urgent risk to users of specific ASUS Live Update clients…
CISA has identified a critical vulnerability, tracked as CVE-2025-59374, in the Asus Live Update tool, which has been exploited as part of a supply chain attack. This flaw allows unauthorized access to systems using the…
The US Government has included ASUS' Live Update software in its 'Known Exploited Vulnerabilities Catalog', indicating that attackers are actively exploiting a vulnerability within the software. Users are advised to…