CISA to allow researchers to report vulnerabilities to exploited bugs catalog
2026-05-25T14:51:54Z•a61721f1819e154b0fd0100b501d97381ccb19bde53d192919fe03939eca1d26
botnetcisaddosfbigeofence searchesincident responsekali365kevkimwolfknown exploited vulnerabilitieslitigationmental healthmetamicrosoft 365oauth token theftphishing-as-a-serviceprivacysupreme courtthreat advisoryvulnerability reporting
What happened
Collection of security and privacy news: CISA launched a nomination form allowing researchers, vendors, and partners to submit bugs for inclusion in the Known Exploited Vulnerabilities (KEV) catalog. The FBI warned about Kali365, a Telegram-based phishing-as-a-service that captures OAuth tokens to enable broad access to Microsoft 365 environments. Separately, a Canadian man was charged for operating the KimWolf DDoS-for-hire botnet that allegedly infected over a million devices. Other items include Meta settling a school-district lawsuit over alleged addictive design harms and a Supreme Court/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- a61721f1819e154b0fd0100b501d97381ccb19bde53d192919fe03939eca1d26
- Enrichment time
- 2026-05-25T14:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.