New: Black Kite Global Adaptive AI Assessment Framework (BK-GA³™), a truly global framework for assessing AI riskGet It Now
BlackKite: Home
Menu

Free TPRM Resources

Your source for primary cybersecurity research from the Black Kite Research Group, thought leadership content on topics that matter today, and more resources to sharpen your TPRM program.

Keyword Search
Filter

RESOURCE TYPE

podcast

The Third-party Cyber Risk Problem No One Talks About

Arbitrary scores and compliance over risk reduction give a false sense of security. Learn how to improve your TPRM program now.

Oct 1, 2025
The Third-Party Cyber Risk Problem No One Talks About
blog

When the Shai-hulud Worm Awakens: Tinycolor’s Fall and the New Era of Supply Chain Risk

In September 2025, the popular npm package @ctrl/tinycolor became the epicenter of a self-propagating supply chain attack, now known as the Shai-Hulud campaign.

Sep 30, 2025
When the Shai-Hulud Worm Awakens: Tinycolor’s Fall and the New Era of Supply Chain Risk
blog

Focus Friday: TPRM Insights on Goanywhere Mft, Solarwinds Web Help Desk, Cisco Snmp, and Dnn Software Vulnerabilities

Welcome to the September 26th edition of Focus Friday, where we analyze some of the most pressing cybersecurity incidents from a Third-Party Risk Management (TP...

Sep 26, 2025
FOCUS FRIDAY: TPRM Insights on GoAnywhere MFT, SolarWinds Web Help Desk, Cisco SNMP, and DNN Software vulnerabilities
knowledge center

Third Party Cyber Risk Management Knowledge Center

Learn how third party cyber risk management (TPCRM) strengthens TPRM, reducing vendor cyber exposure and improving business resilience. Today, third party cyber...

Sep 25, 2025
Third Party Cyber Risk Management Knowledge Center
blog

Focus Friday: TPRM Insights on Jetty, Jenkins, and CUPS Vulnerabilities

Discover how Jetty - MadeYouReset, Jenkins, and CUPS Vulnerabilities: TPRM Insights vulnerabilities impact third-party risk. Black Kite’s FocusTags™ help priori...

Sep 19, 2025
Focus Friday: TPRM Insights on Jetty, Jenkins, and CUPS Vulnerabilities
blog

Focus Friday: TPRM Insights on Sharepoint, Mssql, and Sap Netweaver Critical Vulnerabilities

Discover how Microsoft SharePoint MSSQL SAP NetWeaver Vulnerabilities: TPRM Insights vulnerabilities impact third-party risk. Black Kite’s FocusTags™ help prior...

Sep 12, 2025
Focus Friday: TPRM Insights on SharePoint, MSSQL, and SAP NetWeaver Critical Vulnerabilities
report

Understanding Agentic AI & Protocols: Use Cases, Variants, and Real-world Fit

Sep 11, 2025
Understanding Agentic AI & Protocols: Use Cases, Variants, and Real-World Fit
blog

How to Tackle Third-party Vulnerabilities Without Breaking the Bank

Tackle third-party vulnerabilities without breaking the bank. Discover how to prioritize the risks that actually matter and save millions in remediation costs.

Sep 8, 2025
How to Tackle Third-Party Vulnerabilities Without Breaking the Bank
blog

Focus Friday: TPRM Actions for Django, Freepbx, and Hashicorp Vault Vulnerabilities

TPRM Insights vulnerabilities impact third-party risk. Black Kite’s FocusTags™ help prioritize exposure and streamline TPRM response.

Sep 5, 2025
Focus Friday: TPRM Actions for DJANGO, FREEPBX, and HASHICORP VAULT Vulnerabilities
blog

What the Salesloft Drift Incident Means for TPRM

Salesloft incident highlights the domino effect of third-party breaches. Learn what happened, how to protect your ecosystem from supply chain attacks.

Sep 4, 2025
WHAT THE SALESLOFT DRIFT INCIDENT MEANS FOR TPRM
blog

Focus Friday: TPRM Actions for Critical Citrix Netscaler and Salesforce Tableau Vulnerabilities

Discover how CitrixDeelb Citrix NetScaler Salesforce Tableau Vulnerabilities: TPRM Insights vulnerabilities impact third-party risk. Black Kite’s FocusTags™ hel...

Aug 29, 2025
Focus Friday: TPRM Actions for Critical Citrix NetScaler and Salesforce Tableau Vulnerabilities
blog

Citrixdeelb: What the Latest Citrix Vulnerabilities Mean for TPRM

Citrix vulnerabilities in NetScaler ADC/Gateway are under active exploitation. What happened, what to patch now, and how to manage third-party risk.

Aug 27, 2025
CITRIXDEELB: WHAT THE LATEST CITRIX VULNERABILITIES MEAN FOR TPRM