Contact Info

Location 24 Holborn Viaduct, London EC1A 2BN

Follow Us

Insights from the YUPL team

CREST-certified perspectives on web application security, Laravel engineering, AI integration, and the UK tech market.

AI

When the Best Open-Source Model Is Chinese

By 2026 the top of the Hugging Face leaderboard is a Chinese clean sweep — Qwen3, DeepSeek-V3.2, GLM-4.6, Kimi K2. A UK CREST pen-test firm on what that actually means for product trust, supply-chain risk, and the procurement questions every security team should be asking.

Read →
Security

Project Glasswing and the End of the Annual Pen Test

Anthropic's Project Glasswing, powered by Claude Mythos, found a 27-year-old bug in OpenBSD and a 16-year-old one in FFmpeg in minutes. A UK CREST pen-test firm on what that actually means for your application-layer testing cadence, and the half-life of a zero-day in 2026.

Read →
Security

AI-Generated Code Security Risks: What Pen-Testers Find in 2026

Copilot, Cursor and ChatGPT now write a huge share of production code — and the same seven vulnerabilities keep appearing on every pen test. A CREST-aligned deep-dive into prompt injection, broken auth, SSRF, slopsquatting and the guardrails that actually work.

Read →
AI Security

MCP Server Security Checklist 2026

A practical, CREST-aligned security checklist for MCP servers powering AI agents — auth, tool-call scoping, prompt injection, rate-limits and logging.

Read →
Security Education

OWASP Top 10 Explained (2026)

Complete walkthrough of the 2026 OWASP Top 10 web application vulnerabilities with real-world remediation.

Read →