CISA to allow researchers to report vulnerabilities to exploited bugs catalog

2026-05-24T08:51:54Za42c6311f79353b0e7a2c0dce611c80f80f32dff413b6e372c0edb86ec905956
CISAChatrieDDoS-for-hireFBIKEVKali365KimWolfKnown Exploited VulnerabilitiesMicrosoft 365OAuth token theftSupreme CourtTelegramaddictive designarrestbotnetgeofence searcheslaw enforcementlawsuitmetaphishing-as-a-serviceprivacystudents' mental healthvulnerability disclosure

What happened

Multiple security and legal developments: CISA launched a nomination form allowing researchers, vendors, and partners to submit bugs for inclusion in the Known Exploited Vulnerabilities (KEV) catalog. The FBI warned about Kali365, a Telegram-based phishing-as-a-service that captures OAuth tokens to enable large-scale access to Microsoft 365 environments. Meta settled a school-district lawsuit alleging addictive product design harmed students’ mental health. The Supreme Court’s pending Chatrie decision on geofence searches could materially reshape privacy and law-enforcement search authorities.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
a42c6311f79353b0e7a2c0dce611c80f80f32dff413b6e372c0edb86ec905956
Enrichment time
2026-05-24T08:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA to allow researchers to report vulnerabilities to exploited bugs catalog · Baitaphish