Category: Software Supply Chain

Software Development Security

Software Development Security: A Requirements Checklist With 12 Lines You Can Verify

Most software development security requirements describe a desired state, which means nobody can pass or fail them. Here are 12 written as checks, each with the artifact that proves it.
10 min read
Malicious npm Packages

Malicious npm Packages: The Live List Nobody’s Watching Closely Enough

Malicious npm packages are published faster than registries remove them. What eight weeks of confirmed findings show & what stops them.
8 min read
AI Supply Chain Security

AI Supply Chain Security: How AI Attacks and Defends Code

AI supply chain security defends against slopsquatting, malicious packages, and MCP risks in AI-written code. Learn how!
Zero Trust SDLC

Keys to use AI cybersecurity, Zero Trust SDLC, how to secure AI-generated code, AI Security

Zero Trust SDLC means securing what AI produces and uses. Learn the five surfaces, real attacks, and how to close the AI security gap now.
10 min read
ai inventory software

What Is an AI Inventory? A Practical Guide to AI Asset Discovery, AI-BOM and Shadow AI

What is an AI inventory? A practical guide to AI asset discovery, AI-BOM generation, shadow AI, and EU AI Act compliance.
secure software supply chain, ai bom, mcp security

OWASP Global AppSec EU 2026 Vienna: Key Takeaways on Secure Software Supply Chain, MCP Security, and the AI-BOM

OWASP Vienna 2026 recap: AISVS launch, MCP security gaps, AI-BOM readiness & what the industry is saying about secure software supply chain
5 min read
OWASP GLOBAL Appsec AI Security

AI Security at OWASP Global AppSec EU 2026: Meet Xygeni in Vienna

Xygeni is at OWASP Global AppSec EU 2026, Booth G-08. Live AI Security demos, Zero Trust SDLC, and the team in Vienna. Come by!
7 min read
AI-Driven SDLCs Are Already Here

AI-Driven SDLCs Are Already Here. Now What?

AI-Driven SDLCs Are Already Here. Now What? Learn how to secure AI-driven development with Zero Trust AppSec and full AI visibility.
9 min read
Secure AI-Generated Code

How to Secure AI-Generated Code in CI/CD

Secure AI-Generated Code before it reaches production. Stop vulnerabilities, secrets leaks, and risky dependencies in CI/CD pipelines.
10 min read
AppSec Alert Fatigue

How to Reduce AppSec Alert Fatigue

Understand AppSec alert fatigue and learn how to prioritize real risks, reduce noise, and improve AppSec response with Xygeni.
11 min read
Cloud Security Tips

20 Cloud Security Tips for Modern DevSecOps Teams

Cloud security tips for DevSecOps teams to protect apps, secrets, IaC, CI/CD pipelines, and supply chains.
12 min read
weak application security

How Weak Application Security Creates Digital Privacy Risks

Learn how weak application security exposes data, enabling privacy risks like breaches, impersonation, abuse & how DevSecOps prevent them!
7 min read