Xygeni Blog

what is cve in cyber security - cve security - cve in cyber security

CVE Security Under Pressure: Navigating Challenges and Strengthening Vulnerability Management in DevSecOps

CVE security still anchors vulnerability management, but the system underneath it is straining. 48,185 CVEs were published in 2025, NVD now enriches only the records that meet its criteria, and a growing share of real threats never receive a CVE at all. Here is what breaks, and what to prioritize on instead.
application security audit - open source audit - open source audit software - open source software audit - open source security audit tools

How to Build an Application Security Audit Program That Works: A Practical Guide for DevSecOps

Build an audit-ready application security audit program using open source audit software, CI/CD controls, and real ISO/NIST-aligned evidence.
terraform software -terraform security - terraform iac

Terraform Software: Key FAQs

Discover Terraform software, terraform security, and terraform iac best practices in this FAQ guide to build safe and reliable pipelines.
mitre attack - mitre att&ck - MITRE attack framework - the mitre att&ck framework.

MITRE ATT&CK Framework Explained for Developers

Learn how attack surface management and external attack surface management work in DevSecOps. See why the MITRE ATT&CK framework matters.
jumping shell - bin/bash - escape restricted shell

Jumping Shell: How Attackers Escape Restricted Shells to /bin/bash

Learn how jumping shell exploits let attackers escape restricted shell to /bin/bash, the risks they pose, and how to secure CI/CD pipelines!
package-lock.json - package lock json - npm typosquatting

Package-Lock.json Typo: How It Can Hijack Your Build

A typo in package-lock.json can expose you to NPM typosquatting. Learn how those errors hijack builds and how to secure dependencies!
python try catch - try catch python - try catch block

Python Try Catch Blocks: When Error Handling Becomes a Risk

How Python try catch blocks work, when try catch Python patterns turn risky & best practices to secure your code with safe error handling!
docker-compose.yml - docker-compose secrets

Why Docker-compose.yml Is a Security Risk Surface?

iscover hidden risks in your docker-compose.yml. Learn how to detect and manage docker-compose secrets before they leak into your CI/CD.D
JavaScript Obfuscator - JavaScript deobfuscator - JavaScript malware

Why JavaScript Obfuscator Tools Are Abused by Attackers (And How to Detect Them)

Learn how JavaScript Obfuscator tools are misused to hide JavaScript malware, and how to detect threats before they reach production!
attack surface management - attack surface -external attack surface management

Attack Surface Management in DevSecOps

Learn attack surface management in DevSecOps. Go beyond external attack surface management to cut risks in code, pipelines, and dependencies.
CISA SBOM - SBOM Minimum Elements - SBOM standards - software risk management

CISA SBOM 2025: Updates, Standards, and Compliance

CISA SBOM Minimum Elements 2025: key updates, SBOM standards, and how to align with software risk management.
AI Automated Vulnerability Remediation - code autofix - application security automation - automated application security testing

AI Automated Vulnerability Remediation: Black Hat Replay

AI Automated Vulnerability Remediation with code autofix, application security automation, and automated application security testing.