CISA to allow researchers to report vulnerabilities to exploited bugs catalog

2026-05-26T02:51:53Z676e1e45db870d0f70de0a74e5ef4a4a65b92aae880cc670f06fc88684bd72bd
CISAChatrieDDoSFBIKEVKali365KimWolfKnown Exploited VulnerabilitiesMetaMicrosoft 365OAuth token theftSupreme Courtarrestbotnetgeofence searchlawsuitmental healthphishing-as-a-serviceprivacyvulnerability disclosure

What happened

Multiple cybersecurity and legal developments: CISA launched a nomination form to let researchers, vendors and partners submit bugs for addition to its Known Exploited Vulnerabilities (KEV) catalog. The FBI issued an advisory about Kali365, a Telegram-based phishing-as-a-service that captures OAuth tokens to enable broad Microsoft 365 account access. A Canadian operator of the KimWolf DDoS-for-hire botnet — said to have infected over one million devices — was arrested and charged. Separately, Meta settled a school-district lawsuit alleging addictive product design harmed students’ mentalhealth

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
676e1e45db870d0f70de0a74e5ef4a4a65b92aae880cc670f06fc88684bd72bd
Enrichment time
2026-05-26T02:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.