Xygeni Blog

slsa attestation - slsa framework - SLSA v1.2

SLSA v1.2 : Updates to the SLSA Framework Explained

A clear developer guide to SLSA v1.2 that explains the new requirements, the framework and how to use slsa attestation in your builds.
OWASP Top 10 2025 -owasp top ten - OWASP Top 10

OWASP Top 10 2025 Explained for Developers

A quick developer guide to the OWASP Top 10 2025 that explains the new risks and how to understand them fast.
15 min read
shai hulud - npm supply chain attack

Shai-Hulud 2.0 NPM Supply Chain Attack

Shai Hulud turns the npm supply chain attack into a cross-ecosystem risk. Understand the impact, exposures, and how to stay protected.
15 min read
Vibe Coding Security Risks

AI for Coding Explained: 10 Simple Answers Developers Need

Vibe coding, AI for coding y sus riesgos de seguridad: descubre cĂ³mo proteger tu cĂ³digo de los AI-generated code security risks.
Agentic AI The Complete Guide

Agentic AI: The Complete Guide for Developers, AI Engineers, and AppSec Teams

Learn what agentic AI is and how AI agent platforms and AI coding agents work, including key risks and security practices for DevSecOps.
11 min read
BH EU minimal 16_9

Black Hat Europe 2025: Meet Xygeni at Booth 221

Meet Xygeni at Black Hat Europe 2025. Visit Booth 221 to explore AI AppSec, new product releases and our featured session at BH EU.
dockerfile secrets - dockerfile secrets environment variables

Dockerfile Secrets: Why Layers Keep Your Sensitive Data Forever

Stop leaks from Dockerfile secrets and dockerfile secrets environment variables. Protect builds from exposing credentials in image layers!
docker build args - build args docker - docker build build arg

Docker Build Args: The Hidden Vector for Secret Leaks in Images

Stop secret leaks from Docker Build Args. Learn how build args docker exposes credentials and how to secure your images!
task.run c# - async programming - parallel execution

Task.Run in C#: The Wrong Way to Parallelize Secure Code

Learn how misusing task.run c# breaks async programming and parallel execution, creating security and stability risks in our post!
path traversal attack - file upload vulnerability

Path Traversal in File Uploads: How Developers Create Their Own Exploits

Stop a path traversal attack before it starts. Learn how insecure uploads create a file upload vulnerability and how to secure your handlers.
bepinex.configurationmanager

BepInEx.ConfigurationManager: How Insecure Settings Expose Sensitive Data

Learn how to secure bepinex.configurationmanager settings and prevent leaked tokens or paths with safe config practices and automated checks!
hangfire .net - background job processing c#

Hangfire .NET Jobs: How Background Tasks Create Hidden Vulnerabilities

Secure hangfire .net and background job processing c# by avoiding hidden vulnerabilities, protecting dashboards, and validating job inputs.