CISA to allow researchers to report vulnerabilities to exploited bugs catalog

2026-05-25T20:51:52Zf0529f99de8962a4710ad48cb2d9fd0f68ba9230e8b3ff00796b6e615b815eda
CISADDoSFBIKEVKali365KimWolfKnown Exploited VulnerabilitiesMetaMicrosoft 365OAuth token theftSupreme Courtbotnetgeofence searchesincident responselaw enforcementlitigationmental healthphishing-as-a-serviceprivacyvulnerability disclosure

What happened

Feed of cybersecurity and tech news: CISA created a nomination form to allow researchers and vendors to report bugs for inclusion in the Known Exploited Vulnerabilities (KEV) catalog; the FBI issued an advisory about Kali365, a Telegram-based phishing-as-a-service that captures OAuth tokens to gain broad Microsoft 365 access; a Canadian man was arrested for operating the KimWolf DDoS-for-hire botnet that infected over one million devices; Meta settled a school-district lawsuit alleging addictive design harmed students; and the Supreme Court’s Chatrie case on geofence searches could reshape U.S

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
f0529f99de8962a4710ad48cb2d9fd0f68ba9230e8b3ff00796b6e615b815eda
Enrichment time
2026-05-25T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.