Black Kite Blog
Focus Friday: TPRM Insights on Critical Dead.letter (exim), Microsoft Sharepoint, and Mssql Vulnerabilities
TPRM analysis of critical CVEs in Dead.Letter (Exim), Microsoft SharePoint, and MSSQL. See which vendors are exposed and how to prioritize remediation.
May 15, 2026What Ccpa Means for Your Tpcrm Program
For CISOs and GRC teams: here's what CCPA's reasonable and appropriate steps standard means for your vendor oversight program.
May 14, 2026The Canvas Breach Was More Than an Edtech Problem. It Was a Concentration Risk Problem.
Instructures Canvas breach hit ~9,000 institutions and 275M people, exposing how one vendors 41% market share creates industry-wide concentration risk
May 13, 2026Automating Third-party Cyber Risk Management with Black Kite & Torq
Automating third-party cyber risk management with Black Kite & Torq: how the integration turns FocusTag® alerts into automated remediation workflows.
May 12, 2026Focus Friday: TPRM Insights on Critical Vulnerabilities in Cpanel & Whm, Redis, and Ivanti Epmm
TPRM analysis of critical CVEs in cPanel & WHM, Redis, and Ivanti EPMM. See which vendors are exposed and how to prioritize remediation now.
May 8, 2026Two Crq Experts Walked Into a Webinar. Nobody's Heat Map Survived.
Jack Jones and Black Kite CSO Bob Maley on why color-coded risk reporting fails — and how CRQ gives boards language they actually trust.
May 5, 2026Focus Friday: TPRM Insights on Critical Vulnerabilities in Ollama, Langflow, Sonicwall Sonicos, and N8n
TPRM analysis of critical CVEs in Ollama, Langflow, SonicWall SonicOS, and n8n. See which vendors are exposed and how to prioritize the April surge.
May 1, 2026The Breach Already Happened. Your Vendor Just Hasn't Told You Yet.
The breach already happened. Your vendor just hasn't told you yet. Black Kite CSO Bob Maley on three moves CISOs should make to close the disclosure gap now.
Apr 28, 2026After Mythos: Are You Ready for the Vulnerability Deluge?
A perspective on Mythos from Dr. Ferhat Dikbiyik, Chief Research & Intelligence Officer at Black Kite
Apr 22, 2026Your Vendors' Problems Are Now Your Board's Problems: What the 2026 Third-party Breach Report Changes
2026 Third-Party Breach Report reveals a blast radius that doubled YoY, and new hidden threats. Here's how CISOs can translate into executive action.
Apr 21, 2026What Project Glasswing Means for Your Third-party Cyber Risk Program
Anthropic's Project Glasswing changed the TPCRM equation. Here's what autonomous AI vulnerability discovery means for TPCRM programs & how to handle
Apr 16, 2026Key Takeaways From the 2026 Third-party Breach Report: 200,000 Reasons to Rethink Your TPRM Strategy
New data from 200k vendors reveals third-party blast radius at its highest on record. Black Kite's chief researcher shares what TPCRM leaders must do.
Apr 15, 2026