Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Vatican App Data Breach Exposes 700,000 Users

Vatican App Data Breach Exposes 700,000 Users

Posted on July 28, 2026 By CWS

The Vatican’s Click to Pray app recently suffered a significant security breach, exposing personal data of over 700,000 users due to a flaw in its API. This vulnerability allowed unauthorized access to user information, raising concerns about data protection within religious digital platforms.

API Flaw Leads to Data Exposure

Through an unauthenticated API, anyone could access users’ data without logging in, making private information publicly available. Click to Pray, a digital resource for daily prayers and papal content, inadvertently compromised user privacy by not sufficiently securing its API endpoints.

Information such as names, email addresses, and passwords was vulnerable, with some accounts also revealing country details. This situation emerged after ethical hacker BobDaHacker identified and reported the issue, which was later verified by analysts at DarkReading.

Mechanics of the Security Breach

The API flaw, known as an Insecure Direct Object Reference (IDOR), involved sequential user IDs that could be exploited to access user data. Attackers could use a script to collect data en masse, posing significant risks for phishing and impersonation scams.

DarkReading highlighted this as a classic case of insufficient access control, where unauthorized users could gather significant amounts of personal data. The exposed data included not only contact details but also user roles, with some accounts identified as administrative due to low ID numbers.

Implications and Security Recommendations

This incident underscores the critical importance of robust access control in preventing security breaches. The OWASP Top 10 list identifies access control failures as a major threat, suggesting measures like least-privilege access and strict authorization checks.

Users are advised to limit the personal information shared online and to be cautious of unsolicited emails claiming to be from the Vatican or related entities. Employing pseudonyms or anonymizing email addresses can mitigate the impact of such breaches.

Developers are reminded of the necessity to incorporate comprehensive authorization checks within their applications, beyond basic authentication. Organizations must prioritize security assessments and implement thorough testing to protect user data effectively.

Overall, this breach highlights the enduring responsibility organizations face in safeguarding user data, emphasizing the need for continuous security evaluation and prompt response to vulnerabilities.

Cyber Security News Tags:access control, API vulnerability, Click to Pray, Cybersecurity, data breach, IDOR flaw, Phishing, security risks, user data, Vatican

Post navigation

Previous Post: MedusaHVNC Trojan Enables Stealth Control of PCs

Related Posts

SquareX Reveals That Employees Are No Longer The Weakest Link, Browser AI Agents Are SquareX Reveals That Employees Are No Longer The Weakest Link, Browser AI Agents Are Cyber Security News
MacOS Users Targeted by New Phishing Email Scam MacOS Users Targeted by New Phishing Email Scam Cyber Security News
Threat Actors Allegedly Selling Microsoft Office 0-Day RCE Vulnerability on Hacking Forums Threat Actors Allegedly Selling Microsoft Office 0-Day RCE Vulnerability on Hacking Forums Cyber Security News
Microsoft Confirms UAC Bug Breaks App Install On Windows 11 And 10 Versions Microsoft Confirms UAC Bug Breaks App Install On Windows 11 And 10 Versions Cyber Security News
High-Severity Jenkins Vulnerability Allows Unauthenticated DoS via HTTP CLI High-Severity Jenkins Vulnerability Allows Unauthenticated DoS via HTTP CLI Cyber Security News
30 Wind and Solar Farms in Poland Faced Coordinated Cyberattacks 30 Wind and Solar Farms in Poland Faced Coordinated Cyberattacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Vatican App Data Breach Exposes 700,000 Users
  • MedusaHVNC Trojan Enables Stealth Control of PCs
  • NVIDIA Unveils Open Secure AI Alliance for AI Defense
  • Security Risk Advisors Earns CRN Channel Award Nomination
  • Fake Teams Update Grants Hackers Dual PC Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Vatican App Data Breach Exposes 700,000 Users
  • MedusaHVNC Trojan Enables Stealth Control of PCs
  • NVIDIA Unveils Open Secure AI Alliance for AI Defense
  • Security Risk Advisors Earns CRN Channel Award Nomination
  • Fake Teams Update Grants Hackers Dual PC Control

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark