200 new CVEs a day and no realistic way to patch them all
ResearchOur summary
Ryan Dewhurst, CEO of KEVIntel, outlines how his team detects exploited vulnerabilities that have not yet been included in CISA’s catalog. Using a global honeypot network, AI triage, and manual verification, the company has identified over a thousand known exploited vulnerabilities (KEVs) not present in official records. The research highlights challenges faced by organizations in managing the growing volume of daily CVEs—now averaging 200 per day—and emphasizes the importance of prioritizing high-risk exploits. Dewhurst also warns about misleading AI-generated proof-of-concept code and the limitations of relying solely on CISA’s guidance for private-sector security decisions.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.