Xygeni Blog

AI Governance Framework

Building an AI Governance Framework: A Practical Structure

A policy document alone isn't an AI governance framework. Here's the practical structure, inventory, evidence, and controls, that works.
10 min read
AI Security Company

What to Look for in an AI Security Company

AI security companies all claim the same things. Here's the checklist to actually evaluate one, from coverage to data sovereignty.
API Security Best Practices

API Security Best Practices: A Developer’s Checklist

API security best practices developers actually need: a practical checklist covering API protection and API management, before deployment.
10 min read
Risky Business: Self-Deleting npm Packages Explained

Risky Business: The Anti-Proctoring Packages That Delete Themselves

Risky Business: packages that delete themselves within minutes. Xygeni tracked 16 npm packages, 3 payloads, one shared technique. Dive in!
Types of Cyber Security

Types of Cyber Security: A Complete Overview

Check out a complete overview of the types of cyber security: network, application, cloud, endpoint, identity, IoT, AI & operational security
types of cyber threats

Cyber Threats Explained: The Main Types Security Teams Should Know

Dive in to discover the main types of cyber threats security teams face today: malware, secrets leakage, supply chain and AI code attacks.
npm Package Security

npm Package Security: What Changes When Your AI Agent Runs the Install

AI agents now run npm install on their own. See how MEW and Shield secure npm package security. Meet Xygeni at German OWASP Day 2026.
AI Security Posture Management

AI Security Posture Management: Why Discovery Alone Won’t Secure AI-Generated Code

AI-generated code introduces vulnerabilities at scale. See how AI Security Posture Management fixes risk. Meet Xygeni at OWASP Portugal.
developer security

Developer Security Adoption: Why Tools Sit Unused

Developer security adoption fails for predictable reasons. Here's why developers ignore the tools you bought them & what they trust.
Vulnerability Prioritization

Vulnerability Prioritization Is Broken: Why Severity Score Alone Gets You Fixing the Wrong Thing First

Vulnerability prioritization built on severity alone fixes the wrong thing first. Here's what belongs in the ranking. Dive in!
npm worm playbook

The npm Worm Playbook: Same Attack, Three Times in Eight Months

What is an npm worm? Inside the biggest npm worm incidents, the pattern that repeats, and the cooldown window most defenses still miss.
AI Security

AI Security: The Files Nobody Reviews Are Now Your Biggest Attack Surface

AI security: discover every AI asset in your code, catch prompt injection and poisoned skills, and export an AI-BOM before attackers do.