No Vuln Blog
Applied security research, no buzzwords.
Technical articles on penetration testing, vulnerabilities in production, OWASP, LGPD and the Brazilian security market. Written by people who actually break systems in international bug bounty programs.

GuideJun 10, 202613 min
Grey Box Pentest Guide 2026: Why It's the Default Choice
Grey box pentesting in 2026: credentialed methodology, real coverage, when it fits SaaS and fintech, cost, and how it compares with black and white box.
Read article
VulnerabilityJun 9, 202612 min
7-Step Exploit Chain to Full SaaS Admin Takeover
A recent pentest of an established B2B SaaS: 7 small flaws chained into a full pre-auth admin takeover from zero — no user, no password.
Read article
GuideJun 7, 202612 min
Black Box Pentest Guide 2026: When to Use It and When Not To
Black box pentesting in 2026: definition, methodology, real coverage, when SaaS and fintechs should use it, cost, and how it pairs with grey and white box.
Read article
GuideMay 24, 202613 min
Black Box vs Grey Box vs White Box Pentest: Which to Choose?
Black box, grey box and white box pentesting compared: when to choose each approach, typical coverage, relative cost and how to decide in 2026.
Read article
VulnerabilityMay 23, 202611 min
Race Condition in Payments: The Double-Refund Bug
Race conditions in refund endpoints are the most underrated fintech bug. A technical breakdown of the HTTP/2 single-packet attack on financial endpoints.
Read article
VulnerabilityMay 22, 202610 min
JWT alg:none Is Still in Production in 2026. Here's How
JWT alg:none became a meme in 2015. In 2026 it still shows up in production. A breakdown of the 4 modern variants and how to test and fix them.
Read article
VulnerabilityMay 21, 20268 min
BOLA in Fintech: One Endpoint Leaks Every Tenant
In a fintech pentest, one card endpoint let client A read client B's entire transaction history. An anonymized technical breakdown of a BOLA finding.
Read article
ComplianceMay 7, 202612 min
Why Legal LGPD Compliance Isn't Enough for SaaS and Apps
A privacy policy and a legal opinion won't protect your SaaS, app or platform. Why Brazil's LGPD requires technical measures, and what changes in 2026.
Read article
GuideMay 7, 202611 min
Is Your SaaS Really Secure? 9 Uncomfortable Truths for 2026
Is your SaaS secure? 9 uncomfortable truths about B2B SaaS security in 2026: what scanners miss, and why you're probably vulnerable right now.
Read article
MarketMay 7, 202614 min
10 Best Pentest Companies in Brazil (2026) Compared
An honest comparison of 10 pentest companies in Brazil in 2026: methodology, industry focus, price range, deliverables and when to hire each one.
Read article
MarketMay 6, 202611 min
In-House vs Outsourced Pentest for Fintechs (2026)
In-house security team or outsourced pentest for early-stage and Series A fintechs: cost, bias, coverage and when each one makes sense.
Read article
MarketMay 5, 202612 min
Pentest Cost by SaaS Size in Brazil: 2026 Benchmarks by MRR
What B2B SaaS companies in Brazil pay for a pentest in 2026, by MRR (R$ 10k to R$ 1M): real price ranges, scope, ROI and when to hire.
Read article
GuideMay 1, 202612 min
LGPD Compliance for SaaS, Apps and Websites: 2026 Guide
How to make your website, app or SaaS LGPD-compliant in 2026: what Brazil's ANPD enforces, why a privacy policy isn't enough and how to avoid fines.
Read article
GuideMay 1, 202611 min
Data Breach in Brazil: LGPD Fines and How to Avoid Them
Customer data leaked at your SaaS or fintech in Brazil? LGPD fines go up to 2% of revenue (R$ 50M cap). What the law requires and when to notify the ANPD.
Read article
GuideMay 1, 202613 min
Pre-Launch Security Checklist: 12 Must-Haves for SaaS & Apps
A 12-item security checklist for SaaS, fintechs and apps: what has to be in place before your first customer logs in to production.
Read article
GuideApr 30, 202612 min
Website or SaaS Hacked? What to Do in the First 24 Hours
A step-by-step guide to the first 24 hours after an attack on your SaaS, fintech, e-commerce site or app. Incident response in plain English, no jargon.
Read article
GuideApr 29, 202611 min
Developer, Consultant or Firm: Who Should Secure Your SaaS?
In-house security engineer, freelance consultant or specialized firm to protect your SaaS, fintech or app? A comparison of pros, cons and costs.
Read article
GuideApr 28, 202610 min
Is My Platform Secure? 9 Warning Signs for SaaS and Fintech
9 practical warning signs that your SaaS, fintech or e-commerce platform is vulnerable — and you don't need a technical background to check them.
Read article
VulnerabilityApr 26, 202613 min
BOLA, BOPLA and BFLA: The 3 Flaws That Rule APIs in 2026
BOLA, BFLA and BOPLA are the 3 authorization flaws that dominate APIs in 2026. How they work, why scanners miss them, and how to test manually.
Read article
VulnerabilityApr 22, 202614 min
OAuth Account Takeover in SaaS: 5 Patterns Dominating 2026
5 OAuth account takeover patterns behind real B2B SaaS bugs: state confusion, redirect URI fuzzing, code injection, PKCE bypass and implicit/hybrid flow.
Read article
ComplianceApr 20, 202611 min
LGPD Article 46: 7 Technical Measures the ANPD Expects
What Brazil's ANPD treats as adequate technical measures under LGPD Art. 46 in 2026: 7 controls SaaS, fintech and e-commerce must prove to avoid fines.
Read article
MarketApr 18, 20267 min
Pentest vs Security Audit: What Your SaaS Needs in 2026
Pentest vs. security audit for SaaS and fintech in 2026: when to hire each, what they cost, what you get, and how to combine the two.
Read article
MarketApr 15, 20269 min
How Much Does a Pentest Cost in Brazil? 2026 Price Ranges
Pentest pricing in Brazil in 2026: real ranges by company size, scope, testing mode and sector (SaaS, fintech, e-commerce), plus common quoting traps.
Read article