Xygeni Blog

tj-actions/changed-files - CVE-2025-30066 - secret leakage

CVE‑2025‑30066: When tj‑actions/changed‑files Leads to Secret Leakage

CVE-2025-30066 shows how tj-actions/changed-files can cause secret leakage through CI misconfigurations. Learn how to secure your pipeline!
insecure direct object reference - what is IDOR vulnerability

What Happens When You Don’t Lock Object Access? Hello, IDOR Vulnerability

Read our post and learn what is IDOR Vulnerability (insecure direct object reference), why it is important, how to detect & prevent it!
stride threat modeling framework

STRIDE Threat Model: The “What Can Go Wrong?” Framework

STRIDE breaks CI/CD risk into six categories, from spoofing to privilege escalation. See real examples and how developers can apply it today.
what is arp spoofing attack

What Is ARP Spoofing? A No-Nonsense Explainer for Developers

Do you know what ss ARP Spoofing Attack? Discover its risks, prevention strategies and real world examples and stay alert!
GitOps vs DevOps - GitOps tools

GitOps vs DevOps: What Developers See in Projects

GitOps vs DevOps: Learn how GitOps tools like ArgoCD and FluxCD transform deployments, infrastructure, and security in modern Dev workflows!
which of the following may indicate a malicious code attack - how can malicious code spread

Which of the Following May Indicate a Malicious Code Attack?

Which of the following may indicate a malicious code attack? How can malicious code spread? Learn key warning signs and how to stop threats!
How Can Generative AI Be Used in Cybersecurity, will cybersecurity be replaced by AI, cybersecurity remediation

How Can Generative AI Be Used in Cybersecurity?

Learn how generative AI supports cybersecurity remediation and why AI won’t replace security teams anytime soon.
8 min read
cybersecurity checklist- software security checklist - application security best practices checklist- cybersecurity audit checklist

Cybersecurity Checklist for DevOps Teams

Follow this cybersecurity checklist, software security checklist, and application security best practices checklist to secure your SDLC.
7 min read
Bitbucket Security-bitbucket- bitbucket security best practices

Bitbucket Security FAQs: What Every Developer Should Know

Learn how to apply Bitbucket security best practices. Secure your pipelines, repositories, and workflows with expert Bitbucket security
15 min read
What Are the 5 Key Stages of the Resilience Lifecycle Framework (2)

What Are the 5 Key Stages of the Resilience Lifecycle Framework

Learn what are the 5 key stages of resilience lifecycle framework with vulnerability scanning and a trusted cybersecurity framework.
9 min read
how can i prevent the use of my source code - source code security - code integrity- source code security scanning tools

Source Code Security: Best Practices to Protect Your Code Integrity

Prevent the use of your source code with source code security scanning tools and best practices that ensure code integrity across the SDLC.
7 min read
critical system protection

Critical System Protection Starts in Dev, Not in Prod

Learn how to apply shift left security with SAST and SCA to protect critical systems and build secure software development workflows.
9 min read