CISA to allow researchers to report vulnerabilities to exploited bugs catalog
2026-05-23T20:51:54Z•4d7d208defebd9def81c103f19301e6816be519fd63b0a9b7f0a2512366a5e05
CISADDoSFBIKEVKali365KimWolfKnown Exploited VulnerabilitiesMetaMicrosoft 365OAuth token theftSupreme Courtbotnetgeofence searcheslaw enforcementlitigationmental healthphishing-as-a-serviceprivacyschool lawsuitsvulnerability disclosure
What happened
A batch of security news: CISA launched a nomination form to let researchers and vendors request additions to the Known Exploited Vulnerabilities (KEV) catalog; the FBI warned about Kali365, a Telegram-based phishing-as-a-service tool that captures OAuth tokens to enable broad Microsoft 365 access; Meta settled a school-district lawsuit alleging addictive product design harmed students’ mental health; the Supreme Court’s Chatrie geofence-search case could reshape U.S. privacy law; and U.S. authorities charged a Canadian operator of the KimWolf DDoS-for-hire botnet that infected over one millio
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- 4d7d208defebd9def81c103f19301e6816be519fd63b0a9b7f0a2512366a5e05
- Enrichment time
- 2026-05-23T20:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.