Xygeni Blog

AI Attack Surface

The AI Attack Surface Nobody Is Taking into Account

Your AI attack surface grows with every agent-written line of code. See how slopsquatting & poisoned skills exploit it & how to close the gap
rogue by design

Rogue by Design: How a Sandboxed Pre-Release Model Jailbroke Itself and Hacked Hugging Face to Cheat an Exam

An OpenAI model escaped its sandbox and breached Hugging Face on its own, to cheat a benchmark exam. No human attacker. Here's how.
code-quality-scanner-appsec

Code Quality and Code Security Have Been Living in Two Different Tools. They Don’t Have To.

Code smells & vulnerabilities live in the same codebase but get scanned by different tools. See how our Code Quality scanner closes that gap
PointBlank: PyPI RAT Hides C2 in a JSON-Bin Service

PointBlank: a fully-featured Python RAT that ran its command channel through a free note-hosting service

A PyPI package called gcli-control shipped a full Windows RAT openly & ran its command channel through npoint.io instead of a server it owned
AI in Cybersecurity

AI in Cybersecurity: Attack Vector & Defense Tool

AI in cybersecurity cuts both ways: it writes phishing & cuts SOC alert fatigue in half. This post covers both sides of the fight. Dive in!
How to Detect and Eliminate Shadow AI Risk

How to Detect and Eliminate Shadow AI Risk?

Shadow AI risk is already inside your pipelines, with no install and no paper trail. Learn how to detect & eliminate it!
Slopsquatting Evolution

Slopsquatting evolution: From AI Curiosity to Agent RCE

How slopsquatting attacks evolved from a research curiosity in 2023 to autonomous-agent remote code execution in 2026 & what it means.
AI Governance

AI Governance: What It Actually Takes to Get It Right in 2026

AI governance failures cost enterprises millions. Learn why AI governance monitoring & contextual visibility matter more than policy alone
Slopsquatting: How Attackers Weaponize AI Hallucinations

What Is Slopsquatting? How Attackers Weaponize AI Hallucinations

Slopsquatting turns AI hallucinations into supply chain attacks. Learn how it works, why it's effective & how to defend against it.
Security Threats in 2026

Security Threats in 2026: Types, Blind Spots, and Why Attack Surface Discovery Is the Fix

A guide to security threats, types, how they differ from risk, and how attack surface discovery brings SDLC visibility. Dive in!
10 min read
PhantomSync: npm Crypto Packages Hide Wallet Stealer

PhantomSync: eight crypto-developer npm packages hide a delayed, self-persisting dropper

PhantomSync: 8 npm crypto packages hide a delayed dropper that steals wallet keys and exfiltrates via IPFS. IOCs and detection guide.
AI Supply Chain Security

AI Supply Chain Security: How AI Attacks and Defends Code

AI supply chain security defends against slopsquatting, malicious packages, and MCP risks in AI-written code. Learn how!