Black Kite Blog
Why Ransomware Groups Are Zeroing in on SMBs
Ransomware attacks now target SMBs for maximum supply chain disruption. Learn new tactics and how to secure your organization from third-party risks.
Nov 11, 2025
Focus Friday: TPRM Insights on Moveit, Redis, Control Web Panel, Dnn Software, and Xwiki Vulnerabilities
TPRM Insights on MOVEit, Redis, Control Web Panel, DNN Software, and XWiki vulnerabilities from the week of November 3, 2025.
Nov 7, 2025
Your Ransomware Fatigue Is Leaving the Back Door Open
Ransomware fatigue is real – but risky. Discover how third-party risks are leaving your organization exposed and what CISOs can do now.
Nov 6, 2025
Focus Friday: Critical Third-party Risks in Mikrotik Routeros, Apache Tomcat, Hashicorp Vault, and LiteSpeed Plugin
Discover how Mikrotik RouterOS, Apache Tomcat, HashiCorp Vault, and LiteSpeed Plugin vulnerabilities impact third-party risk.
Oct 31, 2025
Resource Roundup: Stop Drowning in CVEs & Prioritize Your Supply Chain Vulnerabilities
Discover the ultimate roundup of free resources on prioritizing third-party vulnerabilities. Stop drowning in CVEs and learn where to focus.
Oct 27, 2025
Focus Friday: Third-party Risks in Samba Server, Atlassian Jira, Tp-link Omada, Minio, Squid Proxy, and Sauter Ey-modulo Vulnerabilities
Discover how F5 BIG-IP APT Risk Microsoft Exchange Server SharePoint Gladinet CentreStack TrioFox and Flowise Vulnerabilities: TPRM Insights vulnerabilities imp...
Oct 24, 2025
How to Avoid Ransomware: a Ciso’s Guide to Outsmarting Attackers
Ransomware attacks through vendor supply chains are rising. Learn 6 agile, attacker-focused tactics CISOs must use to prioritize risk and outsmart threats.
Oct 20, 2025
Focus Friday: TPRM Insights on F5 Big-ip Apt Risk, Exchange Server, Sharepoint, Gladinet, and Flowise Vulnerabilities
Discover how F5 BIG-IP APT Risk Microsoft Exchange Server SharePoint Gladinet CentreStack TrioFox and Flowise Vulnerabilities.
Oct 17, 2025
Nightmare on F5 Street: Deconstructing the F5 Breach and Its Systemic Supply Chain Risk
The F5 source code breach is a massive supply chain risk. See the full TPRM analysis and immediate steps to protect your vendor ecosystem.
Oct 16, 2025
Focus Friday: TPRM Insights on Oracle Ebs, Jenkins, Redis, Draytek Vigor, Zimbra, Elastic, Django, Grafana, Sillytavern, and WP Yoast SEO
Discover how ORACLE EBS JENKINS REDIS DRAYTEK VIGOR ZIMBRA ELASTIC DJANGO GRAFANA SILLYTAVERN and WP YOAST SEO Vulnerabilities: TPRM Insights vulnerabilities im...
Oct 10, 2025
Focus Friday: TPRM Insights on Cisco Asa, Ftd & Ios, Vmware Vcenter, Wd My Cloud, and Formbricks Vulnerabilities
Welcome to the October 3rd edition of Focus Friday, where we explore recent high-profile vulnerabilities through the lens of Third-Party Risk Management (TPRM)....
Oct 3, 2025
When the Shai-hulud Worm Awakens: Tinycolor’s Fall and the New Era of Supply Chain Risk
In September 2025, the popular npm package @ctrl/tinycolor became the epicenter of a self-propagating supply chain attack, now known as the Shai-Hulud campaign.
Sep 30, 2025