Xygeni Blog

AI risk management

AI risk management: two disciplines, one inventory

Four search terms, two completely different jobs. Managing the risk of AI is not the same discipline as using AI for risk management, and most organisations are staffing one while being sold the other. The interesting part is what happens when you realise they are the same programme.
AI Risk Metrics

AI Risk: The Metrics That Tell You Whether Your Agentic AI Strategy Is Working

Every board now asks the same question: what is our AI risk? Most teams answer with adjectives. Here are the AI risk metrics that produce a number, where each one comes from, and what an agentic AI strategy has to cover before any of them mean anything.
AI security threats

Top 10 AI security threats and how to map them

Two things get filed under the same heading and they are not the same problem. Attacks on AI systems and attacks powered by AI need different controls, different owners and different evidence. Ten threats, split into the two halves, and the one step that precedes all of them.
10 min read
Software Development Security

Software Development Security: A Requirements Checklist With 12 Lines You Can Verify

Most software development security requirements describe a desired state, which means nobody can pass or fail them. Here are 12 written as checks, each with the artifact that proves it.
10 min read
AI Red Team Tools

AI Red Team Tools Test What Your Model Says. They Don’t Test What Your Agent Does Next

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
npm Package Vulnerabilities

npm Package Vulnerabilities: How to Find and Fix Them Before They Ship

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
AI Pentesting Tools

AI Pentesting Tools: What to Look For, and What Agentic Pentesting Actually Changes

AI pentesting tools are four different product shapes. What agentic pentesting changes, seven evaluation criteria, and what it cannot do.
Malicious npm Packages

Malicious npm Packages: The Live List Nobody’s Watching Closely Enough

Malicious npm packages are published faster than registries remove them. What eight weeks of confirmed findings show & what stops them.
What Is the Agentic SDLC

What Is the Agentic SDLC? How AI Agents Are Reshaping Every Phase

Agents now plan, code, review, ship and operate. What the agentic SDLC changes in every phase, and which controls quietly stop working.
AI Pentesting

AI Pentesting: Testing AI Systems Like an Attacker Would

Your last pentest tested code. AI pentesting tests behaviour: hijacked prompts, abused tools, leaked data. What to test, and how often.
The CWE Top 25

The CWE Top 25: What It Is and Why It’s Not the Same as the OWASP Top 10

One ranks weaknesses, the other ranks risks. What the CWE Top 25 measures, how it differs from OWASP Top 10, and when to use each.
10 min read
Agentic Coding

Agentic Coding: The Risks, the Best Practices, and 8 Lessons from Early Adopters

Agents now write, install and ship code. The real risks of agentic coding, the practices that contain them & 8 lessons learned the hard way.
10 min read