CISA to allow researchers to report vulnerabilities to exploited bugs catalog
2026-05-22T20:51:56Z•f07a882d49fd4047e553f41ee71fab7d8baf13e4ca76dc3226a78fd321824a8a
CISADDoSDOJFBIKEVKali365KimWolfKnown Exploited VulnerabilitiesMetaMicrosoft 365OAuth token theftSupreme CourtTelegrambotnetgeofence searcheslaw enforcementlegal settlementmental healthphishing-as-a-serviceprivacyvulnerability reporting
What happened
Multiple security and legal developments: CISA announced a public nomination form enabling researchers, vendors and partners to submit bugs for inclusion in the Known Exploited Vulnerabilities (KEV) catalog. The FBI issued an advisory on Kali365, a Telegram-based phishing‑as‑a‑service that captures OAuth tokens to enable broad access to Microsoft 365 tenants. The DOJ unsealed charges against a Canadian man, Jacob Butler, for operating the KimWolf DDoS-for-hire botnet that infected over one million devices. Separately, Meta reached a settlement with a school district over claims its product设计s[
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- f07a882d49fd4047e553f41ee71fab7d8baf13e4ca76dc3226a78fd321824a8a
- Enrichment time
- 2026-05-22T20:51:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.