CISA to allow researchers to report vulnerabilities to exploited bugs catalog

2026-05-22T14:51:52Z8b1e301e3b5b87bfc8252e76809b3d67314294983e7650a362db95cb5963631a
BelarusCISAGhostWriterIndiaKEVKnown Exploited VulnerabilitiesOfcomUkraineUnimedcall centerschild safetydata breachhealthcaremalwaremisprision of a felonyphishingsocial mediatech support scamthird-party providervulnerability reporting

What happened

Multiple cybersecurity developments: CISA launched a nomination form allowing researchers, vendors and partners to propose bugs for inclusion in the Known Exploited Vulnerabilities (KEV) catalog. Belarus-linked GhostWriter actors ran a phishing/espionage campaign against Ukrainian officials using fake online-training certificate emails to deliver malware. A large-scale data breach at German hospitals occurred via third-party billing provider Unimed, exposing patient and billing data. UK tech platforms (Roblox, Snapchat, Instagram/Facebook, YouTube, TikTok) pledged changes to satisfy Ofcom on兒d

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
8b1e301e3b5b87bfc8252e76809b3d67314294983e7650a362db95cb5963631a
Enrichment time
2026-05-22T14:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA to allow researchers to report vulnerabilities to exploited bugs catalog · Baitaphish