CISA to allow researchers to report vulnerabilities to exploited bugs catalog
2026-05-25T08:51:56Z•77a98416b4242bd8190880288579441146f6933420370de74740452f32408fdb
CISADDoSDDoS-for-hireFBIKali365KimWolfKnown Exploited VulnerabilitiesMetaMicrosoft 365OAuth token theftSupreme Court Chatriebotnetgeofence searchesmental healthphishing-as-a-serviceprivacyschool lawsuitvulnerability reporting
What happened
A batch of security and privacy stories: CISA launched a nomination form to let researchers, vendors and partners submit bugs for addition to the Known Exploited Vulnerabilities (KEV) catalog, expanding reporting pathways. The FBI warned about Kali365, a Telegram-based phishing‑as‑a‑service that captures OAuth tokens to enable widespread Microsoft 365 account takeover. A Canadian suspect was charged for operating the KimWolf DDoS‑for‑hire botnet that infected over a million devices. Separately, legal developments: Meta settled a school‑district lawsuit alleging addictive design harmed students
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- 77a98416b4242bd8190880288579441146f6933420370de74740452f32408fdb
- Enrichment time
- 2026-05-25T08:51:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.