How to Implement AI Remediation in DevSecOps

Implement AI remediation in DevSecOps to reduce vulnerability noise, improve remediation decisions, and automate safer fixes. Free checklist included.
Shadow AI Security: All You Need to Know

Shadow AI security is changing fast. See the OpenClaw takeovers, skills supply chain risks, and the exact DevSecOps fixes to apply this quarter.
New npm Infostealer Discovery: Nyx Stealer Hijacks Discord Sessions

Xygeni identifies Nyx: a sophisticated npm Infostealer hijacking Discord and crypto wallets using advanced runtime decryption.
Xygeni Launches MCP Server for AI Security in the IDE

Discover the mcp server and its role in orchestrating security with AI to transform how developers handle code generation.
Malicious npm Package in Baileys Fork (Skyzopedia Case)

Malicious npm package abuses a Baileys fork to inject runtime spam behavior through a GitHub-controlled payload.
React2Shell: CVE-2025-55182 and the Next.js RCE Risk

React2Shell (CVE-2025-55182) creates a critical Next.js RCE risk. Understand the impact and what to patch immediately.
Shai-Hulud: The npm Packages Worm Explained

Shai-Hulud npm worm: Read all you need to know about this massive supply chain attack with the latest updates and IoCs.
Open Source Malicious Packages: The Problem

Explore our blog series by CTO Luis Rodriguez on identifying open-source malicious packages and safeguarding your organization from supply chain attacks.
NPM flooding case-study: “Down the Rabbit Hole looking for a Tea”

Discover the intriguing NPM flooding case-study “Down the Rabbit Hole looking for a Tea” by José Antonio Garcel Díaz, revealing hidden anomalies and security insights. Read the full article now!
XZ Backdoor: “That was a close one”

Explore Luis Rodríguez’s analysis of the XZ Backdoor attack: A stealthy SSH vulnerability exposed and contained, revealing crucial cybersecurity lessons.