<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Veritus Code · Blog</title><description>Technical guides, methodology and lessons from real web application, API and mobile assessments. The blog of Veritus Code, a penetration testing consultancy for SMBs and startups.</description><link>https://blog.verituscode.com/</link><language>en</language><item><title>What security you will be asked for before integrating with a bank or gateway</title><link>https://blog.verituscode.com/en/blog/security-requirements-bank-payment-integration/</link><guid isPermaLink="true">https://blog.verituscode.com/en/blog/security-requirements-bank-payment-integration/</guid><description>Questionnaires, a recent pentest, PCI DSS and evidence: what banks, payment processors and enterprise clients usually require from a fintech, and how to prepare without slowing the business down.</description><pubDate>Sun, 08 Nov 2026 00:00:00 GMT</pubDate><category>fintech</category><category>pci-dss</category><category>compliance</category><category>pentesting</category><category>startups</category></item><item><title>The 5 vulnerabilities we see again and again in fintech APIs</title><link>https://blog.verituscode.com/en/blog/fintech-api-vulnerabilities/</link><guid isPermaLink="true">https://blog.verituscode.com/en/blog/fintech-api-vulnerabilities/</guid><description>IDOR on transfers, mass assignment of balances, race conditions, unlimited OTP attempts and forgotten versions: what they are, how to test them and how to fix them.</description><pubDate>Sun, 25 Oct 2026 00:00:00 GMT</pubDate><category>api</category><category>fintech</category><category>owasp</category><category>pentesting</category><category>bola</category></item><item><title>What CVEs, CVSS and the rest of the acronyms actually mean</title><link>https://blog.verituscode.com/en/blog/what-are-cves/</link><guid isPermaLink="true">https://blog.verituscode.com/en/blog/what-are-cves/</guid><description>CVE, CWE, CVSS, EPSS, KEV… We explain in plain terms what each acronym means, how a vulnerability is scored, and how to decide which ones to fix first.</description><pubDate>Sun, 11 Oct 2026 00:00:00 GMT</pubDate><category>cve</category><category>cvss</category><category>vulnerabilities</category><category>nvd</category><category>risk-management</category></item><item><title>Our web application pentesting methodology, step by step</title><link>https://blog.verituscode.com/en/blog/web-pentesting-methodology/</link><guid isPermaLink="true">https://blog.verituscode.com/en/blog/web-pentesting-methodology/</guid><description>How we assess a web application end to end: scope, reconnaissance, mapping, analysis, controlled exploitation and a report the client actually understands.</description><pubDate>Wed, 30 Sep 2026 00:00:00 GMT</pubDate><category>pentesting</category><category>methodology</category><category>owasp</category><category>recon</category><category>burp-suite</category></item></channel></rss>