Black Kite Blog
Focus Friday: TPRM Insights on Critical Vulnerabilities in Kiteworks, Citrix Netscaler, Mikrotik Routeros, Openssl, and WordPress Core
Black Kite's Focus Friday covers critical flaws in Kiteworks, Citrix NetScaler, MikroTik, OpenSSL, and WordPress, and what TPRM teams should do now.
Oct 2, 20262,300 Mythos Vulnerabilities Disclosed. 421 Patched. That Gap Is in Your Supply Chain.
Mythos has disclosed 2,300 vulnerabilities to open-source maintainers. Only 421 are patched. That backlog is third-party cyber risk you don't control.
Sep 25, 2026Focus Friday: TPRM Insights on Critical Vulnerabilities in Screenconnect, Exim, Citrix Netscaler, Apache Tomcat, and Langflow
TPRM analysis of critical ScreenConnect, Exim, Citrix NetScaler, Apache Tomcat, and Langflow vulnerabilities and how to prioritize vendor remediation.
Sep 25, 2026Supply Chain Incident Response Starts Before the Incident
Supply chain incident response starts too late. Jeffrey Wheatman on making the decisions, automation, and vendor paths ready before a supplier gets hit.
Sep 15, 2026Focus Friday: TPRM Insights on Critical Vulnerabilities in N-central, Adobe Commerce & Magento, Mikrotik, Fortinet, Mssql, Sharepoint, Exchange Server, Mongodb, Roundcube, and Jenkins
TPRM analysis of critical N-central, Adobe Commerce & Magento, MikroTik, Fortinet, MSSQL, SharePoint, Exchange Server, MongoDB, Roundcube, and Jenkins. See whic...
Sep 11, 2026Focus Friday: TPRM Insights on Critical Vulnerabilities in Papercut Mf/ng, Sonicwall Sma1000, Sangoma Switchvox, and Mongodb Bi Connector
TPRM analysis of critical PaperCut MF/NG, SonicWall SMA1000, Sangoma Switchvox, and MongoDB BI Connector. See which vendors are exposed and how to prioritize re...
Sep 4, 2026Black Kite Shortlisted for the Risk Management Awards 2026
Black Kite has been shortlisted for Cyber Security Product of the Year at the Risk Management Awards 2026, recognizing its contribution to the risk management p...
Sep 3, 2026Focus Friday: TPRM Insights on Critical Vulnerabilities in Trueconf, Openssl, Apache Tomcat, Postgresql, and WordPress Elementor
TPRM analysis of critical TrueConf, OpenSSL, Apache Tomcat, PostgreSQL, and WordPress Elementor. See which vendors are exposed and how to prioritize remediation...
Aug 28, 2026Patchmageddon Is Here. What Are Your Vendors Doing About It?
JPMorgan's Patchmageddon report tackles AI-accelerated vulnerabilities in your own environment. Here's the third-party question it leaves open.
Aug 26, 2026Working Exploits Now Cost $3.61. Reactive Defense Can't Survive That.
Field notes from the Black Hat 2026 briefings: $3.61 exploits, autonomous agent attacks, and poisoned packages. What cheap offense means for third-party risk.
Aug 25, 2026Focus Friday: TPRM Insights on Critical Vulnerabilities in Citrix Netscaler, Vmware Vcenter, Zimbra, Oracle Weblogic, and Roundcube
TPRM analysis of critical CVEs in Citrix NetScaler, VMware vCenter, Zimbra, Oracle WebLogic, and Roundcube. See which vendors are exposed and how to prioritize ...
Aug 21, 2026Ransomware Groups Are Vibe-coding Their Way Past Old Defenses
Ransomware crews now vibe-code encryptors, skip paid recon tools, and let AI triage stealer logs. Here’s what’s actually changed in the attack chain.
Aug 19, 2026