Skip to main content
New 2026 Ransomware Report: Why Every Year Becomes the Worst Year on RecordRead the Report
BlackKite: Home
Menu

Black Kite Blog

Keyword Search
blog

Focus Friday: TPRM Insights on Critical Vulnerabilities in Trueconf, Openssl, Apache Tomcat, Postgresql, and WordPress Elementor

TPRM analysis of critical TrueConf, OpenSSL, Apache Tomcat, PostgreSQL, and WordPress Elementor. See which vendors are exposed and how to prioritize remediation...

Aug 28, 2026
blog

Patchmageddon Is Here. What Are Your Vendors Doing About It?

JPMorgan's Patchmageddon report tackles AI-accelerated vulnerabilities in your own environment. Here's the third-party question it leaves open.

Aug 26, 2026
blog

Working Exploits Now Cost $3.61. Reactive Defense Can't Survive That.

Field notes from the Black Hat 2026 briefings: $3.61 exploits, autonomous agent attacks, and poisoned packages. What cheap offense means for third-party risk.

Aug 25, 2026
blog

Focus Friday: TPRM Insights on Critical Vulnerabilities in Citrix Netscaler, Vmware Vcenter, Zimbra, Oracle Weblogic, and Roundcube

TPRM analysis of critical CVEs in Citrix NetScaler, VMware vCenter, Zimbra, Oracle WebLogic, and Roundcube. See which vendors are exposed and how to prioritize ...

Aug 21, 2026
blog

Ransomware Groups Are Vibe-coding Their Way Past Old Defenses

Ransomware crews now vibe-code encryptors, skip paid recon tools, and let AI triage stealer logs. Here’s what’s actually changed in the attack chain.

Aug 19, 2026
blog

Offense Got Faster at Black Hat 2026. Defense Has to Get Connected.

Black Hat 2026 talked about AI. DEF CON broke 20-year-old protocols. Why collective resilience, not individual speed, is the answer to third-party cyber risk.

Aug 17, 2026
blog

Focus Friday: TPRM Insights on Critical Vulnerabilities in Rockwell Plcs, Metabase, Cisco Asa & Ftd, Cisco Imc, Cisco Ios Xe, Adobe Coldfusion, Sharepoint, Exchange Server, Clamav, Pgadmin, Django, and Jenkins

TPRM analysis of critical CVEs in Rockwell PLCs, Metabase, Cisco ASA & FTD, Cisco IMC, Cisco IOS XE, Adobe ColdFusion, SharePoint, Exchange Server, ClamAV, pgAd...

Aug 14, 2026
blog

Focus Friday: TPRM Insights on Critical Vulnerabilities in Teamcity, Cisco Fmc, Solarwinds Web Help Desk, N-central, Langflow, Apache Tomcat, and Gitea

TPRM analysis of critical CVEs in TeamCity, Cisco FMC, SolarWinds Web Help Desk, N-central, Langflow, Apache Tomcat, and Gitea. See which vendors are exposed an...

Aug 7, 2026
blog

Three Years of Ransomware Susceptibility Index Data Say Your Questionnaire Is Guessing

See three years of Ransomware Susceptibility Index data behind Black Kite's 2026 Ransomware Report, and why it outperforms self-graded vendor questionnaires.

Aug 3, 2026
blog

Focus Friday: TPRM Insights on Critical Vulnerabilities in WordPress, Nginx, Solarwinds Serv-u, Oracle Weblogic, Zimbra, Exim, Rabbitmq, Langflow, Gitea, Sharepoint

TPRM analysis of critical CVEs in WordPress, NGINX, SolarWinds Serv-U, Oracle WebLogic, Zimbra, Exim, RabbitMQ, Langflow, Gitea, SharePoint. See which vendors a...

Jul 24, 2026
blog

Focus Friday: TPRM Insights on Critical Vulnerabilities in Progress Sharefile Szc, Sonicwall Sma1000, Mssql, Exchange Server, Zimbra, Roundcube, Freebsd, and Sharepoint

TPRM analysis of critical CVEs in Progress ShareFile SZC, SonicWall SMA1000, MSSQL, Exchange Server, Zimbra, Roundcube, FreeBSD, and SharePoint.

Jul 17, 2026
blog

Sharefile's Silent Zero-day: Inside Progress's Emergency Storage Zone Controller Shutdown

TPCRM analysis of the unpatched path traversal in Progress ShareFile Storage Zone Controller. See exposure scope and how to prioritize remediation.

Jul 16, 2026

Ready to connect cyber risk intelligence to your entire risk program?

Integrate risk intelligence into every part of your workflow so you can make more informed decisions with confidence.