Category: Open-Source Security

npm Package Vulnerabilities

npm Package Vulnerabilities: How to Find and Fix Them Before They Ship

Uncover the details of The 24712-pl Campaign and the zero-dependency packages exploited during a security incident.
9 min read
npm Package Security

npm Package Security: What Changes When Your AI Agent Runs the Install

AI agents now run npm install on their own. See how MEW and Shield secure npm package security. Meet Xygeni at German OWASP Day 2026.
7 min read
Xygeni AI Shield

Xygeni AI Shield: Stop AI-Generated Malicious Packages

AI tools now write and publish malicious packages in minutes. See how Xygeni AI Shield blocks them before they execute. Free plan available.
8 min read
Autofix in AppSec

Autofix in AppSec: How to Remediate Vulnerabilities Without Breaking Builds

Autofix in AppSec helps remediate vulnerabilities automatically while avoiding breaking changes. Learn how to fix issues safely in DevSecOps.
15 min read
Why We Built Known-Exploit Intelligence Fix What Attackers Actually Use

Known-Exploit Intelligence for Vulnerability Management

Discover how Known-Exploit Intelligence can transform your vulnerability management by prioritizing confirmed attack behaviors.
4 min read
Why PURL Matters More Than You Think

Why purl Matters More Than You Think

Learn how purl and pkg improve vulnerability assessment by identifying dependencies accurately and reducing false positives in modern SCA.
7 min read
Risk Based Vulnerability Management- cyber resilience act - cisa known exploited vulnerabilities catalog

Risk Based Vulnerability Management and CRA

Risk based vulnerability management explained using the CISA Known Exploited Vulnerabilities Catalog and the Cyber Resilience Act.
9 min read
Vibe Coding Security Risks

AI for Coding Explained: 10 Simple Answers Developers Need

Vibe coding, AI for coding y sus riesgos de seguridad: descubre cómo proteger tu código de los AI-generated code security risks.
6 min read
Agentic AI The Complete Guide

Agentic AI: The Complete Guide for Developers, AI Engineers, and AppSec Teams

Learn what agentic AI is and how AI agent platforms and AI coding agents work, including key risks and security practices for DevSecOps.
11 min read
MCP Security

MCP Security: Protecting the Model Context Protocol

Learn model context protocol and MCP security basics plus server security best practices for safer AI–DevOps.
6 min read
Spring Boot security - Java Spring Boot - Spring Boot security best practices

Spring Boot Security FAQs

Learn key Spring Boot security best practices to protect Java apps, APIs, and CI/CD pipelines with automation and real visibility.
9 min read
dependency check - owasp dependency check - dependency mapping tool - application dependency mapping tools

Dependency Check Tools in AppSec

Explore dependency check tools and modern dependency mapping tools. Learn how Xygeni automates detection, prioritization, and fixes.
6 min read