<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
	<title>Uphack Application Security Blog</title>
	<link>https://uphack.io/blog/</link>
	<description>Practical AppSec research, secure engineering lessons, exploit breakdowns, and security career advice.</description>
	<language>en-gb</language>
	<atom:link href="https://uphack.io/blog/rss.xml" rel="self" type="application/rss+xml" />
	<lastBuildDate>Fri, 24 Jul 2026 00:00:00 GMT</lastBuildDate>
<item>
	<title>WP2Shell: Pre-Auth WordPress RCE (CVE-2026-63030), Reproduced</title>
	<link>https://uphack.io/blog/post/wp2shell-unauthenticated-wordpress-core-rce/</link>
	<guid isPermaLink="true">https://uphack.io/blog/post/wp2shell-unauthenticated-wordpress-core-rce/</guid>
	<pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate>
	<description>WP2Shell is an unauthenticated remote code execution chain in WordPress core, combining CVE-2026-63030 and CVE-2026-60137. What it is, how to fix and detect it, and how to reproduce the full pre-auth RCE in a hands-on lab.</description>
</item>
<item>
	<title>Fundamental security principles</title>
	<link>https://uphack.io/blog/post/fundamental-security-principles/</link>
	<guid isPermaLink="true">https://uphack.io/blog/post/fundamental-security-principles/</guid>
	<pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate>
	<description>This post is all about the “big ideas” behind secure systems, like least privilege and separation of duties. These principles are surprisingly simple but form the backbone of how we design systems to stay safe from attacks.</description>
</item>
<item>
	<title>You Are the Bottleneck Now</title>
	<link>https://uphack.io/blog/post/you-are-the-bottleneck-now/</link>
	<guid isPermaLink="true">https://uphack.io/blog/post/you-are-the-bottleneck-now/</guid>
	<pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate>
	<description>AI can now generate code, fixes, and explanations faster than most developers can properly evaluate them. That sounds like a productivity breakthrough. It may also be the fastest way to become a worse engineer without noticing.</description>
</item>
<item>
	<title>The Illusion of Building</title>
	<link>https://uphack.io/blog/post/the-illusion-of-building/</link>
	<guid isPermaLink="true">https://uphack.io/blog/post/the-illusion-of-building/</guid>
	<pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate>
	<description>AI makes it dramatically cheaper to produce software that appears to work. But &apos;building an app&apos; and &apos;engineering a system&apos; are two different activities that people keep confusing, and the gap between them is where most of the actual work lives.</description>
</item>
<item>
	<title>Security Is Not a Code Problem</title>
	<link>https://uphack.io/blog/post/security-is-not-a-code-problem/</link>
	<guid isPermaLink="true">https://uphack.io/blog/post/security-is-not-a-code-problem/</guid>
	<pubDate>Sun, 22 Feb 2026 00:00:00 GMT</pubDate>
	<description>Security is having a moment: new tools can read code, find bugs, and even suggest fixes. Some people took that to mean cybersecurity is basically over. This is my take from the inside: what’s actually changing, what isn’t, and why security was never just a code problem.</description>
</item>
<item>
	<title>Access Controls: Auth and Authz</title>
	<link>https://uphack.io/blog/post/access-control-authentication-and-authorization/</link>
	<guid isPermaLink="true">https://uphack.io/blog/post/access-control-authentication-and-authorization/</guid>
	<pubDate>Sat, 21 Feb 2026 00:00:00 GMT</pubDate>
	<description>How do systems make sure the right people get in, and the wrong ones stay out? In this post, we’ll dig into authentication (proving who you are) and authorization (what you’re allowed to do). They’re simple ideas, but they have a massive impact on security. </description>
</item>
<item>
	<title>Foundations of Information Security - CIA Triad</title>
	<link>https://uphack.io/blog/post/foundations-of-information-security-cia-triad/</link>
	<guid isPermaLink="true">https://uphack.io/blog/post/foundations-of-information-security-cia-triad/</guid>
	<pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate>
	<description>The CIA triad isn’t just a catchy acronym. It’s the backbone of security. We’ll break down confidentiality, integrity, and availability, and see how they shape the way we think about protecting systems and data. </description>
</item>
<item>
	<title>Introduction to Information Security</title>
	<link>https://uphack.io/blog/post/introduction-to-information-security/</link>
	<guid isPermaLink="true">https://uphack.io/blog/post/introduction-to-information-security/</guid>
	<pubDate>Sat, 14 Feb 2026 00:00:00 GMT</pubDate>
	<description>We cannot start a meaningful exploration of computer security without defining the subject itself. In this post, we&apos;ll talk about what security actually means.</description>
</item>
<item>
	<title>How to start your offensive security career</title>
	<link>https://uphack.io/blog/post/how-to-start-your-offensive-security-career/</link>
	<guid isPermaLink="true">https://uphack.io/blog/post/how-to-start-your-offensive-security-career/</guid>
	<pubDate>Sun, 09 Mar 2025 00:00:00 GMT</pubDate>
	<description>Is hacking like in the movies? How do I start? What do I need to know? What skills should I have? These are...</description>
</item>
</channel>
</rss>