200 new CVEs a day and no realistic way to patch them all KEVIntel CEO Ryan Dewhurst reports that the company's global honeypot sensor network, AI triage, and human verification lab confirm exploitation of vulnerabilities not yet listed in CISA's Known Exploited Vulnerabilities catalog, as the volume of 200 new CVEs per day makes patching all of them unrealistic. Dewhurst discusses CISA's three-day patching deadline under BOD 26-04, the role of virtual patching to buy time, and how AI-generated proof-of-concept code complicates evidence analysis. Ryan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability reaches the public feed. He covers CISA’s three-day patching deadline under BOD 26-04, why virtual patching buys time, and how AI-generated proof-of-concept code muddies the evidence. He also ranks incident reports, honeypot hits, scanning and PoC chatter by how … More https://www.helpnetsecurity.com/2026/07/30/ryan-dewhurst-kevintel-known-exploited-vulnerabilities/ The post 200 new CVEs a day and no realistic way to patch them all https://www.helpnetsecurity.com/2026/07/30/ryan-dewhurst-kevintel-known-exploited-vulnerabilities/ appeared first on Help Net Security https://www.helpnetsecurity.com .