Identifying and Managing Software Dependencies Attacks

Discover how to identify and defend against all types of software dependency attacks.
Typosquatting vs. Copycat Packages: Understanding the Differences

Understand the differences between typosquatting and copycat packages, both tactics used to deceive users into downloading malicious software.
What is Malicious Code and How Does it Work?

Discover the insidious world of malicious code: from backdoors to ransomware. Learn how to safeguard your digital assets with advanced cybersecurity measures.
Spotlighted in ‘Software Supply Chain Security Deep-Dive,’ we redefine cybersecurity with innovative solutions and real-time protection.
The Ledger Attack: draining hardware cryptowallets

Delve into the Ledger Attack, a spear-phishing SSC incident dissected by Xygeni’s expert Luis Manuel Rodriguez Berzosa, revealing lessons in security, impact assessment, and incident response.
10 Malicious NPM Packages Uncovered: A 2024 Case Study Still Relevant Today

Uncover malicious NPM packages and fortify your software supply chain with Xygeni’s Early Warning Service. 10 malicious NPM packages were discovered and a new threat vector, djs13-fetcher, was identified. Learn how to protect your business from these threats.
Strengthening Telco Defenses Against Supply Chain Attacks

Uncover the risk of supply chain attacks on telecoms, safeguard data, and embrace Software Bill of Materials (SBOM) for supply chain security.
Bad.Build: The Latest Google Cloud Bug Threatening the Software Supply Chain

Introduction Orca Security has recently identified a design flaw in Google Cloud Build service, named “Bad.Build.” This flaw poses a serious security risk as it enables attackers to execute Privilege Escalation, granting them unauthorized entry into Google’s Artifact Registry’s code repositories. The consequences of this vulnerability extend to the software supply chain, as attackers can […]
3CX Supply Chain Attack: Lessons Learned

Software Supply Chain Attacks Analysis 3CXÂ is a well-known company providing VoIP and Unified Communications products. They claim to have over 600,000 installations and 12M daily users. Undoubtedly a tempting target for bad actors. By the end of March, 3CX suffered the 3CX Supply Chain Attack a sophisticated software supply chain attack, which managed to […]
Prevent Code Tampering in Four Steps

Code tampering refers to the unauthorised modification or alteration of source code during software application development, testing, or deployment. This malicious activity can have devastating consequences, from introducing security vulnerabilities to altering the intended behaviour of the software, causing it to fail in unexpected ways. Code tampering prevention is a serious concern for businesses in today’s […]
Software Supply Chain Attacks: Should I be worried?

Software technology evolved, and hackers evolved with it. The arms-race with bad actors was mostly restricted to vulnerabilities and attacks directed at the deployed software. Attacking the software supply chain, albeit not unseen, was not the primary target for the bad guys… The attack many addressed as the start of a shift in the Advanced […]