CISA to allow researchers to report vulnerabilities to exploited bugs catalog
2026-05-23T02:51:56Z•bb1261a7852275b73bc7f27fa523642fe20cfff6a19fa040490dfaa0aaf6e2da
CISAChatrieDDoSDDoS-for-hireFBIKEVKali365KimWolfKnown Exploited VulnerabilitiesMetaMicrosoft 365OAuth token theftSupreme CourtTelegramarrestbotnetgeofence searchesincident advisorylawsuitphishing-as-a-serviceprivacystudent mental healthtoken capturevulnerability disclosure
What happened
Collection of security and privacy developments: CISA announced a nomination form to allow researchers, vendors, and partners to request that actively exploited bugs be added to the Known Exploited Vulnerabilities (KEV) catalog. The FBI published an advisory on Kali365, a Telegram-based phishing‑as‑a‑service that captures OAuth tokens to enable large‑scale Microsoft 365 access, following April M365 attacks. Legal and privacy news includes Meta settling a school‑district lawsuit over alleged addictive design harms to students and an upcoming Supreme Court decision in the Chatrie case that could
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- bb1261a7852275b73bc7f27fa523642fe20cfff6a19fa040490dfaa0aaf6e2da
- Enrichment time
- 2026-05-23T02:51:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.