Meet us a Black Hat! Become a Black Kite Ranger to help protect the cyber ecosystem.Learn more
BlackKite: Home
Menu

Black Kite Blog

Keyword Search
blog

Focus Friday: TPRM Insights on Critical Vulnerabilities in Teamcity, Cisco Fmc, Solarwinds Web Help Desk, N-central, Langflow, Apache Tomcat, and Gitea

TPRM analysis of critical CVEs in TeamCity, Cisco FMC, SolarWinds Web Help Desk, N-central, Langflow, Apache Tomcat, and Gitea. See which vendors are exposed an...

Aug 7, 2026
blog

Three Years of Ransomware Susceptibility Index Data Say Your Questionnaire Is Guessing

See three years of Ransomware Susceptibility Index data behind Black Kite's 2026 Ransomware Report, and why it outperforms self-graded vendor questionnaires.

Aug 3, 2026
blog

Why Ransomware Accelerated 60% in Six Months

Ransomware volume jumped 60% from April-Sept. 2025 to Oct. 2025-March 2026, hitting an all-time high of 861 victims in March. Here's why the surge happened.

Jul 28, 2026
blog

Focus Friday: TPRM Insights on Critical Vulnerabilities in WordPress, Nginx, Solarwinds Serv-u, Oracle Weblogic, Zimbra, Exim, Rabbitmq, Langflow, Gitea, Sharepoint

TPRM analysis of critical CVEs in WordPress, NGINX, SolarWinds Serv-U, Oracle WebLogic, Zimbra, Exim, RabbitMQ, Langflow, Gitea, SharePoint. See which vendors a...

Jul 24, 2026
blog

Focus Friday: TPRM Insights on Critical Vulnerabilities in Progress Sharefile Szc, Sonicwall Sma1000, Mssql, Exchange Server, Zimbra, Roundcube, Freebsd, and Sharepoint

TPRM analysis of critical CVEs in Progress ShareFile SZC, SonicWall SMA1000, MSSQL, Exchange Server, Zimbra, Roundcube, FreeBSD, and SharePoint. See which vendo...

Jul 17, 2026
blog

Sharefile's Silent Zero-day: Inside Progress's Emergency Storage Zone Controller Shutdown

TPCRM analysis of the unpatched path traversal in Progress ShareFile Storage Zone Controller. See exposure scope and how to prioritize remediation.

Jul 16, 2026
blog

Focus Friday: TPRM Insights on Critical Vulnerabilities in Joomshaper Sp Page Builder, Langflow, and Apache Activemq

TPRM analysis of critical CVEs in JoomShaper SP Page Builder, Langflow, and Apache ActiveMQ. See which vendors are exposed and how to prioritize remediation.

Jul 10, 2026
blog

Focus Friday: TPRM Insights on Critical Vulnerabilities in Sharepoint, Proftpd, Cacti, and Gogs

TPRM analysis of critical CVEs in SharePoint, ProFTPD, Cacti, and Gogs. See which vendors are exposed and how to prioritize remediation.

Jul 2, 2026
blog

Dora's First Year of Data Is In. Third Parties Are Still the Weak Link.

DORA's grace period is over. The ESAs' first major incident report is out — and third-party ICT risk is driving the gaps. Here's what your program needs now.

Jul 1, 2026
blog

Focus Friday: TPRM Insights on Critical Vulnerabilities in Squidbleed, Unifi Os Devices, Freebsd, Pgadmin, and Tinyproxy

TPRM analysis of critical CVEs in Squidbleed, UniFi OS Devices, FreeBSD, pgAdmin, and TinyProxy. See which vendors are exposed and how to prioritize remediation...

Jun 26, 2026
blog

The Vulnerability Deluge Has a Business Problem That TPRM Teams Can't Solve Without the C-suite

Black Kite research identified 58 CVEs out of 48,000 that threaten supply chains. But which exposed vendors are operationally irreplaceable? Only the C-suite ca...

Jun 23, 2026
blog

Focus Friday: TPRM Insights on Nginx Rift, Langflow, Jenkins, Mongodb, LiteSpeed Cpanel Plugin, Simplehelp, and Fortibleed Breach

TPRM analysis of critical CVEs in Nginx Rift, Langflow, Jenkins, MongoD, Litespeed Cpanel Plugin, SimpleHelp, and FortiBleed Breach. See which vendors are expos...

Jun 18, 2026

Ready to connect cyber risk intelligence to your entire risk program?

Integrate risk intelligence into every part of your workflow so you can make more informed decisions with confidence.