Xygeni Blog

AI Security Risks in DevSecOps

AI Security Risks in DevSecOps: Code, Pipelines, and Agents

Explore AI security risks in DevSecOps and understand how they affect the software development lifecycle and automation processes.
12 min read
EVMDeFi npm Typosquatting Attack Steals Developer Keys

EVM/DeFi npm Typosquatting Attack Steals Developer Keys

A npm typosquatting attack used six malicious EVM/DeFi packages to steal developer keys, wallets, secrets, and .env files.
FauxCode When Your Reverse-Engineered Claude Code Quietly Routes Through the Attacker

FauxCode: Reverse-Engineered Claude Code Routes Through Attackers

FauxCode Claude Code npm malware used fake CLI packages to intercept API traffic through CA-bundle MITM and base URL hijacking.
DevTap npm Typosquatting Attack

DevTap npm Typosquatting Attack: Six Malicious Packages Target Developer Workstations

DevTap npm typosquatting attack used six malicious packages to spy on developer workstations and abuse npm trust.
Secure AI-Generated Code

How to Secure AI-Generated Code in CI/CD

Secure AI-Generated Code before it reaches production. Stop vulnerabilities, secrets leaks, and risky dependencies in CI/CD pipelines.
10 min read
AppSec Alert Fatigue

How to Reduce AppSec Alert Fatigue

Understand AppSec alert fatigue and learn how to prioritize real risks, reduce noise, and improve AppSec response with Xygeni.
11 min read
Cloud Security Tips

20 Cloud Security Tips for Modern DevSecOps Teams

Cloud security tips for DevSecOps teams to protect apps, secrets, IaC, CI/CD pipelines, and supply chains.
12 min read
MTTR

MTTR in AppSec: How to Reduce it with AI & Automation

Stop the backlog. Reduce MTTR with AI-driven remediation, automate fixes, and move from detection to resolution in minutes.
inject environment variables to the build process

Inject Environment Variables to the Build Process Securely

Inject environment variables to the build process securely. Learn how to prevent leaks and protect secrets in CI/CD pipelines.
Axios npm Compromise

Axios npm Compromise: What Happened, Who Is Affected, and How to Prevent It

Axios npm compromise explained. Discover how attackers access secrets and how to prevent runtime data leaks.
Global InfoSec Awards

Xygeni Wins Two Global InfoSec Awards for ASPM and GenAI Application Security

Xygeni wins two Global InfoSec Awards for ASPM and GenAI Application Security with DevAI and code-to-cloud risk prioritization.
ReDoS

ReDoS Explained: What Regular Expression DoS Is and How to Prevent It

ReDoS attacks can crash your apps. Discover how vulnerable regex patterns work and how to detect and prevent them with modern AppSec practices.