CISA to allow researchers to report vulnerabilities to exploited bugs catalog
2026-05-23T08:51:52Z•d303fb247c26f45b1cca96f5bc33c6af08242f285260a404b12fe741534dc12e
CISADDoSFBIKEVKali365KimWolfKnown Exploited VulnerabilitiesMicrosoft 365 compromiseOAuth token theftbotnetgeofencelaw enforcementlitigationmetaphishing-as-a-serviceprivacyvulnerability disclosure
What happened
This collection highlights several security and privacy developments: CISA launched a nomination form allowing researchers, vendors, and partners to report bugs for inclusion in the Known Exploited Vulnerabilities (KEV) catalog; the FBI warned about Kali365, a Telegram-based phishing-as-a-service that captures OAuth tokens to enable widespread Microsoft 365 compromise; a Canadian operator was charged for running the KimWolf DDoS-for-hire botnet that infected over a million devices; a high-profile settlement by Meta in a school-district lawsuit over addictive design and student harm; and a U.S.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- d303fb247c26f45b1cca96f5bc33c6af08242f285260a404b12fe741534dc12e
- Enrichment time
- 2026-05-23T08:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.