CISA to allow researchers to report vulnerabilities to exploited bugs catalog

2026-05-22T20:51:56Zf07a882d49fd4047e553f41ee71fab7d8baf13e4ca76dc3226a78fd321824a8a
CISADDoSDOJFBIKEVKali365KimWolfKnown Exploited VulnerabilitiesMetaMicrosoft 365OAuth token theftSupreme CourtTelegrambotnetgeofence searcheslaw enforcementlegal settlementmental healthphishing-as-a-serviceprivacyvulnerability reporting

What happened

Multiple security and legal developments: CISA announced a public nomination form enabling researchers, vendors and partners to submit bugs for inclusion in the Known Exploited Vulnerabilities (KEV) catalog. The FBI issued an advisory on Kali365, a Telegram-based phishing‑as‑a‑service that captures OAuth tokens to enable broad access to Microsoft 365 tenants. The DOJ unsealed charges against a Canadian man, Jacob Butler, for operating the KimWolf DDoS-for-hire botnet that infected over one million devices. Separately, Meta reached a settlement with a school district over claims its product设计s[

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
f07a882d49fd4047e553f41ee71fab7d8baf13e4ca76dc3226a78fd321824a8a
Enrichment time
2026-05-22T20:51:56Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.