CVE Tools

200 new CVEs a day and no realistic way to patch them all

Help Net SecurityBy Mirko Zorz

Research

Our summary

Ryan Dewhurst, CEO of KEVIntel, outlines how his team detects exploited vulnerabilities that have not yet been included in CISA’s catalog. Using a global honeypot network, AI triage, and manual verification, the company has identified over a thousand known exploited vulnerabilities (KEVs) not present in official records. The research highlights challenges faced by organizations in managing the growing volume of daily CVEs—now averaging 200 per day—and emphasizes the importance of prioritizing high-risk exploits. Dewhurst also warns about misleading AI-generated proof-of-concept code and the limitations of relying solely on CISA’s guidance for private-sector security decisions.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store