CISA to allow researchers to report vulnerabilities to exploited bugs catalog
2026-05-22T08:51:54Z•1cc02cbf83c0da94cae1f1b0a3d4ad7ce4a56912002638a0fab803bc8514d810
CISAFacebookFirst VPNInstagramKEVKnown Exploited VulnerabilitiesOfcomRobloxSnapchatTikTokUK cybercrime lawVPN takedownYouTubecall forwardingchild safetyinternational operationlaw enforcementmisprision of a felonyransomwaresecurity researchsocial media platformstech support scamstelemarketing fraudvulnerability disclosure
What happened
A batch of cybersecurity developments: CISA launched a nomination form enabling researchers, vendors and partners to report bugs for inclusion in its Known Exploited Vulnerabilities (KEV) catalog. UK proposals to reform cybercrime law could severely restrict security research by forcing researchers to stop activity as soon as a vulnerability is found, raising concerns about disclosure and exploitability assessments. European authorities dismantled First VPN, a service marketed on Russian-speaking forums that helped criminals hide ransomware and other attacks. Two U.S. residents pleaded guilty—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- 1cc02cbf83c0da94cae1f1b0a3d4ad7ce4a56912002638a0fab803bc8514d810
- Enrichment time
- 2026-05-22T08:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.