Xygeni Blog

DAST Meets ASPM

DAST Meets ASPM: Closing the Gap Between Code and Runtime Exposure

DAST meets ASPM to correlate runtime exposure with code risk, reduce false positives, and prioritize exploitable vulnerabilities.
AI-Powered Malware Detection

AI-Powered Malware Detection in SSCS

AI-powered malware detection stops ai malware through behavioral analysis and protects code, dependencies, and CI/CD pipelines.
OWASP GenAI Security Project - generative AI security - gen AI security

OWASP GenAI Security Project

Guide for DevOps on the OWASP GenAI Security Project, generative AI security, and gen AI security risks in modern CI/CD pipelines.
Shai-Hulud 3.0 - npm Malware Worn - shai-hulud malware

Shai-Hulud 3.0: npm Malware Worm

Shai-Hulud 3.0 is the latest shai-hulud npm malware, a worm that spreads automatically through npm packages.
weak application security

How Weak Application Security Creates Digital Privacy Risks

Learn how weak application security exposes data, enabling privacy risks like breaches, impersonation, abuse & how DevSecOps prevent them!
application control engine - application client container - aspm

Application Control Engine vs Client Container in ASPM

Discover how an application control engine, application client container, and (ASPM) enable real execution control.
Broken Access Control - Security Misconfiguration - Managed Object Browser

Managed Object Browser and Broken Access Control

Security advisory on Managed Object Browser risks, Security Misconfiguration, and Broken Access Control aligned with OWASP A05:2021.
Why PURL Matters More Than You Think

Why purl Matters More Than You Think

Learn how purl and pkg improve vulnerability assessment by identifying dependencies accurately and reducing false positives in modern SCA.
Risk Based Vulnerability Management- cyber resilience act - cisa known exploited vulnerabilities catalog

Risk Based Vulnerability Management and CRA

Risk based vulnerability management explained using the CISA Known Exploited Vulnerabilities Catalog and the Cyber Resilience Act.
mcp server - model context protocol - mcp ai project

MCP Server in AI: Key Concepts Explained

Learn what an MCP server is, how the Model Context Protocol works, and how to secure an MCP AI project safely.
software supply chain security - open source supply chain attacks - AI and software security - AI Security

AI Security and the Expanding Software Supply Chain Attack Surface

AI Security is now inseparable from software supply chain security. Learn what AI-driven development means for dependency risk.
10 min read
React2Shell - CVE-2025-55182 - RCE risk

React2Shell: CVE-2025-55182 and the Next.js RCE Risk

React2Shell (CVE-2025-55182) creates a critical Next.js RCE risk. Understand the impact and what to patch immediately.