CISA to allow researchers to report vulnerabilities to exploited bugs catalog
2026-05-24T14:51:55Z•554e4b28497ae5a833ea23bad94f35d77c0e42e9df778a36e5b5b5a11b7937c5
CISADDoSFBIKEVKali365KimWolfKnown Exploited VulnerabilitiesMetaMicrosoft 365OAuthSupreme_Courtbotnetcloud_securitygeofencelaw_enforcementlitigationphishing-as-a-serviceprivacyvulnerability_reporting
What happened
Multiple security developments: CISA launched a nomination form allowing researchers, vendors and partners to submit bugs for inclusion in the Known Exploited Vulnerabilities (KEV) catalog, streamlining reporting of actively exploited flaws. The FBI issued an advisory on Kali365, a Telegram-based phishing-as-a-service that captures legitimate OAuth tokens to enable large-scale access to Microsoft 365 environments — a significant threat to orgs relying on cloud identity. Separately, U.S. authorities unsealed charges against a Canadian operator of the KimWolf DDoS-for-hire botnet that allegedly—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- 554e4b28497ae5a833ea23bad94f35d77c0e42e9df778a36e5b5b5a11b7937c5
- Enrichment time
- 2026-05-24T14:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.