Xygeni Blog

CICD-Pipelines

A Deep Dive into CI/CD Pipelines Vulnerabilities (III): Artifact Poisoning and Code Injection

This post deep dives into some other CI/CD pipeline vulnerabilities such as Artifact Poisoning and Code Injection. Don't miss out!
Implementing CI/CD Best Practices for Success

CI/CD Best Practices: Transforming Software Development

CI/CD practices transform the way development teams squash bugs, improve software quality, and speed up the delivery of updates,... Read More
12 min read
create sbom - sbom generation tools -sbom security

How to Create SBOM with Xygeni – SBOM Security

What belongs in an SBOM, how SPDX and CycloneDX differ, what the Cyber Resilience Act requires, and how to generate one automatically on every build.
The SBOM Revolution: How Transparency Transforms Compliance and Supercharges Software Security

SBOM Security: Strengthening Software Compliance and Protection

Why is software security important, and how can SBOM help supercharge your software security and improve compliance? Take a quick peek!
Coffee Talk SSCS 2024

Unveiling the Future of Software Supply Chain Security: Insights from Industry Leaders

Dscover the Future of Software Supply Chain Security: in an era marked by the exponential rise of cyber threats, safeguarding SSCS is key!
Common Compliance Pitfalls in Software Supply Chain Security

Common Compliance Pitfalls in Software Supply Chain Security

In this blog post we will talk about some of the most common compliance pitfalls in Software Supply Chain Security. Take a look!
poisoned-pipeline-execution-II

A Deep Dive into CI/CD Pipelines Vulnerabilities (II) : Indirect Poisoned Pipeline Execution (I-PPE)

Poisoned Pipeline Execution (PPE) is produced when the attacker can modify the pipeline logic in either of two ways: discover which!
The Ledger Attack: draining hardware cryptowallets

The Ledger Attack: draining hardware cryptowallets

This post analyzes Ledger attack as an example of how a spear phising led to a software supply chain (SSC) attack on the software connect-kit
10 Malicious NPM Packages Uncovered: A Wake-up Call to Software Supply Chain Security

10 Malicious NPM Packages Uncovered: A 2024 Case Study Still Relevant Today

Xygeni's 2024 discovery of 10 malicious npm packages was an early warning sign. Today: 100-200+ weekly. See what changed!
Brewing Security Resilience: A Coffee Talk on Software Supply Chain Security in 2024

Brewing Security Resilience: A Coffee Talk on Software Supply Chain Security in 2024

Join us for a free thought-provoking coffee talk on the future of Software Supply Chain Security in 2024. Register Now!
aspm security - application security posture management

ASPM – Application Security Posture Management: Elevating Cybersecurity & Business Success

Discover ASPM security. Learn how application security posture management strengthens defenses, ensures compliance & prevents cyber threats!
what is an SBOM Security - Software Security

SBOM Security and Its Role in Software Security

One crucial tool gaining prominence is SBOM Security. But what exactly is SBOM, and why is it so vital for software security?