Welcome to the flock! 🖤 We had six new additions to the team in the month of August! We're so happy to have you all here. Jack Barre, Enterprise Account Executive Osman Doğan, Data Engineer Vanessa Flores (Parada), Senior Digital Customer Success Program Manager Suchi Karn, Product Manager Jonathan Mack, Manager, Sales Development Jason Videll, Senior Director, Partner Technology Strategy & Enablement Want to join our team? We're hiring: https://lnkd.in/gUJhQr76
Black Kite
Computer and Network Security
Boston, Massachusetts 15,609 followers
Collective Resilience for Third-Party Cyber Risk Management
About us
Black Kite is an AI-native third-party cyber risk management platform built for the connected world. By distilling billions of external risk signals from millions of monitored organizations, Black Kite delivers the trusted intelligence that powers a connected defense network, enabling organizations to identify risk earlier, act faster, and move from isolated defense to collective resilience. With Black Kite, organizations benefit from greater control, earlier warning, and the confidence to work safely with third parties at scale.
- Website
-
https://blackkite.com/
External link for Black Kite
- Industry
- Computer and Network Security
- Company size
- 51-200 employees
- Headquarters
- Boston, Massachusetts
- Type
- Privately Held
- Founded
- 2016
- Specialties
- Vulnerability Management, Targeted Cyber Threat Intelligence, Continuous Perimeter Monitoring, CyberSecurity, Cyber Risk Management, Cyber Insurance, Third Party Risk Management, Third Party Cyber Risk, Continuous Monitoring, Vendor Management, Supply Chain Risk Management, Due Diligence, and Reputational Risk
Locations
-
Primary
Get directions
800 Boylston St
Suite 2904
Boston, Massachusetts 02199, US
Employees at Black Kite
Updates
-
A vendor breach doesn't stay a vendor breach. It becomes your incident response call, your downtime, your ransomware event. Join us and New Tech Solutions Inc on Wednesday, Sept. 16 at 2 p.m. EST / 11 a.m. PST for a live look at how organizations are getting ahead of third-party ransomware exposure. What we'll cover: 🔹 Why point-in-time vendor assessments miss what matters 🔹 How continuous monitoring turns vendor risk into a decision you can act on 🔹 Practical steps to identify, prioritize and mitigate exposure across your supply chain Featuring Megan R., our Ransomware SME and former FBI Cyber Special Agent, bringing frontline investigation experience to today's threat landscape. Save your seat: https://lnkd.in/gZ8HudMU #TPCRM #ThirdPartyRisk #Ransomware #SupplyChainSecurity #Cybersecurity
-
-
"Black Kite would be the number one product I would recommend. The level of trust has greatly increased and we have just better visibility and it's more accurate and it's more timely." Matthew Mudry, CISO at Alera Group, Inc., shares what changed after plugging their critical vendors into Black Kite: real-time alerts, faster vendor approvals, and conversations with vendors that actually go somewhere. Check out his full story in the comments 👇
-
Five FocusTags this week. CVSS won't tell you which one to act on first. TrueConf is the urgent one — both CVEs are in CISA's KEV catalog, and Head Mare swapped the legitimate client installer for a trojanized version. One vendor's server becomes everyone's problem. 🔹 TrueConf — 9.8 + 9.0 unauth RCE chain, actively exploited 🔹 Apache Tomcat — 3 of 11 CVEs hit 100% of 187,461 exposed instances 🔹 PostgreSQL — 8.8, public PoC, code exec from a standard connection 🔹 Elementor — 9.0 unauth file upload, mass-exploit campaigns 🔹 OpenSSL — 9 CVEs, mostly DoS, no confirmed exploitation Ferdi Gül and Hakan K. have the full breakdown for you with remediation recommendations ⬇️
-
It's roundup time. The August edition of Free TPRM Resources brings you new insights to help you stay informed and sharpen your vendor risk program. Inside: 🔷 Why Black Hat’s AI tracks and DEF CON's old-school hacks prove defense has to get connected 🔷 Three years of Ransomware Susceptibility data say your vendor questionnaire is guessing 🔷 A follow-up Mythos webinar replay on TPCRM in the Age of AI 🔷 How ransomware groups are vibe-coding their way past old defenses 🔷 How cheap AI-driven offense has gotten ($3.61 a working exploit) Read the full roundup and keep an eye on Black Kite for more helpful resources throughout the year. #ThirdPartyRisk #TPRM #CyberRisk #BlackHat2026
-
Finding them was never the hard part. Verifying, disclosing and patching them is, and that bottleneck is what third-party cyber risk teams should be planning around. The good news: your limited remediation capacity may be closer to sufficient than it looks, if you aim it correctly. Read the article and watch the episode to learn more. #TPCRM #ThirdPartyRisk #CyberRisk #VulnerabilityManagement #SupplyChainSecurity #AI
-
$3.61 and 21.5 minutes. That's the average cost and time researchers reported at Black Hat 2026 to produce a working exploit for a Linux kernel vulnerability. When offense gets that cheap, patch cadence stops being a useful measure of vendor resilience. Ferdi Gül and Ekrem Selçuk Çelik report back on what the briefings at Black Hat actually showed: 🔷 An AI agent collective that chained real zero-days and escalated to cluster-admin in under 13 hours 🔷 A cross-cloud extortion case that ran end to end in three days using only native tooling, no custom malware 🔷 52,000+ new npm versions published daily, and why removing a poisoned package doesn't end the incident The takeaway for third-party cyber risk teams: your real exposure is the union of your vendors' dependency trees, not the vendor list you assess. Check out their notes from the field ⬇️
-
Five FocusTags this week, spanning remote access, virtualization, email, and application servers. Two carry confirmed active exploitation. One has a public PoC. All five sit on infrastructure that manages other systems. 🔷 Citrix NetScaler CVE-2026-8452 (CVSS 9.8): pre-auth RCE as root via SAML signature canonicalization. watchTowr published a working PoC. 🔷 VMware vCenter CVE-2026-59309 & CVE-2026-59310: auth bypass chained with directory traversal RCE for full unauthenticated takeover. 361 victim IPs across 47 countries in six days, with reverse_ssh deployed for persistence. 🔷 Zimbra CVE-2026-73570: unauthenticated command injection, confirmed exploited by CERT Polska, with web shells landing in Jetty webapps directories. 🔷 Oracle WebLogic: eight CVEs in one CPU cycle, all unauthenticated takeover via T3 and IIOP, up to CVSS 9.9. 🔷 Roundcube 1.6.18 / 1.7.3: RCE in the markasjunk plugin plus two SSRF bypasses. Eleven bugs, no CVEs assigned yet. Ferdi Gül and Hakan K. have the full breakdown for you: https://lnkd.in/gjGpPehv
-
-
A snapshot. A questionnaire. A single point in time. That's what most tools hand you. Meanwhile your suppliers, their partners, and everyone downstream keep changing, and that risk becomes yours whether you can see it or not. Jeffrey Wheatman shares what it takes to actually keep up. See every supplier. See every risk. Because no organization should have to defend alone. Book a demo ⬇️