CISA to allow researchers to report vulnerabilities to exploited bugs catalog
2026-05-26T02:51:53Z•676e1e45db870d0f70de0a74e5ef4a4a65b92aae880cc670f06fc88684bd72bd
CISAChatrieDDoSFBIKEVKali365KimWolfKnown Exploited VulnerabilitiesMetaMicrosoft 365OAuth token theftSupreme Courtarrestbotnetgeofence searchlawsuitmental healthphishing-as-a-serviceprivacyvulnerability disclosure
What happened
Multiple cybersecurity and legal developments: CISA launched a nomination form to let researchers, vendors and partners submit bugs for addition to its Known Exploited Vulnerabilities (KEV) catalog. The FBI issued an advisory about Kali365, a Telegram-based phishing-as-a-service that captures OAuth tokens to enable broad Microsoft 365 account access. A Canadian operator of the KimWolf DDoS-for-hire botnet — said to have infected over one million devices — was arrested and charged. Separately, Meta settled a school-district lawsuit alleging addictive product design harmed students’ mentalhealth
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- 676e1e45db870d0f70de0a74e5ef4a4a65b92aae880cc670f06fc88684bd72bd
- Enrichment time
- 2026-05-26T02:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.