Xygeni Blog

LiteLLM Supply Chain Attack

LiteLLM Attack: How Xygeni Stops Secret Exposure Fast

LiteLLM attack exposed critical secrets. See how Xygeni detects, verifies, and revokes credentials before attackers use them.
7 min read
LiteLLM Supply Chain Attack

LiteLLM Supply Chain Attack: How TeamPCP Backdoored AI Infrastructure

Explore the security breach of LiteLLM, affecting millions of users with multi-stage payloads and devastating consequences.
AI Coding Assistant Security

AI Coding Assistant Security: How to Prevent Vulnerabilities in AI-Generated Code

AI coding assistant security guide: prevent vulnerabilities in AI-generated code, detect risks early, and secure your pipelines in real time.
7 min read
How to Implement AI Remediation

How to Implement AI Remediation in DevSecOps

Explore how AI remediation enhances DevSecOps by prioritizing security fixes to reduce risk effectively and efficiently.
7 min read
Shadow AI Security

Shadow AI Security: All You Need to Know

Shadow AI security: OpenClaw takeovers, skills supply chain risk, and DevSecOps fixes you can ship this quarter.
9 min read
npm Infostealer

New npm Infostealer Discovery: Nyx Stealer Hijacks Discord Sessions

Xygeni identifies Nyx: a sophisticated npm Infostealer hijacking Discord and crypto wallets using advanced runtime decryption.
7 min read
Xygeni Launches MCP Server for AI Security in the IDE

Xygeni Launches MCP Server for AI Security in the IDE

Discover the mcp server and its role in orchestrating security with AI to transform how developers handle code generation.
3 min read
Malicious npm Package

Malicious npm Package in Baileys Fork (Skyzopedia Case)

Malicious npm package abuses a Baileys fork to inject runtime spam behavior through a GitHub-controlled payload.
5 min read
Mobile App Security

Mobile App Security with Swift and Kotlin SAST

Strengthen mobile app security with native Swift SAST and Kotlin SAST, optimized for OWASP Mobile Top 10 and CI/CD integration.
5 min read
allintextlogin filetypelog

allintext:login filetype:log – How Exposed Logs Leak Credentials

allintext:login filetype:log exposes public log files with credentials and tokens. Learn how to stop log-based data leaks.
6 min read
vibe coding

Vibe Coding Security: Why Traditional AppSec Breaks

Vibe coding security exposes blind spots in traditional AppSec. Learn how to secure AI-driven DevSecOps workflows.
6 min read
Why We Built Known-Exploit Intelligence Fix What Attackers Actually Use

Known-Exploit Intelligence for Vulnerability Management

Discover how Known-Exploit Intelligence can transform your vulnerability management by prioritizing confirmed attack behaviors.
4 min read