VulnCheck is proud to be a Coffee sponsor of GrrCON 2026, which takes place in Grand Rapids Sept 24-26. Stop by for coffee and connect with the VulnCheck team.
Also catch Patrick's Garrity's talk on Trust But Verify: The Messy Reality of Exploitation Evidence
Since 2021, CISA's Known Exploited Vulnerabilities (KEV) catalog has become one of the most trusted signals in vulnerability prioritization. But behind the simple label of "exploited in the wild" is a messy, inconsistent, and often misunderstood ecosystem of evidence.
In this talk, Patrick will break down where exploitation signals actually come from: honeypots and canaries to IDS/IPS detections, payloads, vendor advisories, security researchers, and exploit databases, forums, and social media, and what each source can and cannot tell defenders.