Daily Digest

CISA KEV Alerts, Windows Defender Exploits, and Axios Supply Chain Attack Dominate Threat Landscape

CISA KEV Alerts, Windows Defender Exploits, and Axios Supply Chain Attack Dominate Threat Landscape

April 20, 2026
9 articles (6 new, 3 updated)
27 min read

Summary

This week in cybersecurity, CISA added eight actively exploited vulnerabilities to its KEV catalog, demanding urgent patching for products from Cisco, JetBrains, and PaperCut. Security researchers confirmed that three exploits targeting Windows Defender, including two unpatched flaws, are being used in live attacks to gain SYSTEM-level privileges. A major supply chain attack compromised the popular Axios NPM library, injecting a remote access trojan into dependent applications. Other significant events include the discovery of the 'DarkSword' iPhone zero-day, new data breach claims from LockBit and ShinyHunters, and Microsoft's massive April Patch Tuesday addressing over 160 vulnerabilities.

Filter by Category

New Articles (6)

Updated Articles (3)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.