<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Summit security research</title><description>Penetration testing case studies, hardening guides and compliance explainers from Summit.</description><link>https://sumrite.com/</link><language>en</language><item><title>Your API reflects any Origin in Access-Control-Allow-Origin. Here is how to fix it.</title><link>https://sumrite.com/blog/cors-misconfiguration-reflected-origin/</link><guid isPermaLink="true">https://sumrite.com/blog/cors-misconfiguration-reflected-origin/</guid><description>Fix a CORS misconfiguration where Access-Control-Allow-Origin reflects any Origin, such as evil.com. Risk rating, safe tests and secure configs for every stack.</description><pubDate>Tue, 06 Oct 2026 00:00:00 GMT</pubDate><category>Security Hardening</category><category>CORS</category><category>API Security</category><category>Security Headers</category><category>Web Application Security</category><category>Hardening</category></item><item><title>How to remove the IIS Server header including Microsoft-HTTPAPI/2.0.</title><link>https://sumrite.com/blog/remove-iis-server-header/</link><guid isPermaLink="true">https://sumrite.com/blog/remove-iis-server-header/</guid><description>Remove the IIS Server header (Microsoft-IIS/10.0) and Microsoft-HTTPAPI/2.0 from HTTP.sys, plus X-Powered-By and X-AspNet-Version, on every IIS version.</description><pubDate>Tue, 06 Oct 2026 00:00:00 GMT</pubDate><category>Security Hardening</category><category>IIS</category><category>Windows Server</category><category>Security Headers</category><category>Information Disclosure</category><category>Hardening</category></item><item><title>Secure, HttpOnly and SameSite cookies: which flags to set and why.</title><link>https://sumrite.com/blog/secure-cookie-flags-samesite/</link><guid isPermaLink="true">https://sumrite.com/blog/secure-cookie-flags-samesite/</guid><description>Secure cookie flags explained: Secure, HttpOnly and SameSite Strict vs Lax vs None, which to pick for each cookie, and how to set them in every major framework.</description><pubDate>Tue, 06 Oct 2026 00:00:00 GMT</pubDate><category>Security Hardening</category><category>Cookies</category><category>Session Management</category><category>CSRF</category><category>Security Headers</category><category>Hardening</category></item><item><title>How to remove the AWS ALB server header and stop advertising your stack.</title><link>https://sumrite.com/blog/disable-aws-alb-server-header/</link><guid isPermaLink="true">https://sumrite.com/blog/disable-aws-alb-server-header/</guid><description>Remove the AWS ALB server header (awselb/2.0) with the routing.http.response.server.enabled listener attribute: console, CLI and Terraform steps.</description><pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate><category>Security Hardening</category><category>AWS</category><category>ALB</category><category>Security Headers</category><category>Information Disclosure</category><category>Hardening</category></item><item><title>A competitor downloaded all their customer data. Here is how it happened.</title><link>https://sumrite.com/blog/how-idor-exposed-customer-records/</link><guid isPermaLink="true">https://sumrite.com/blog/how-idor-exposed-customer-records/</guid><description>IDOR vulnerability case study: sequential IDs in a SaaS API let a competitor download 12,000 customer records. How it was found, exploited and fixed in 4 hours.</description><pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate><category>Case Studies</category><category>IDOR</category><category>OWASP API1</category><category>Access Control</category><category>SaaS Security</category><category>API Security</category></item></channel></rss>