Vatican's Click to Pray App Leaked 700,000+ Users' Data for Six Months Before Being Quietly Fixed
An unauthenticated API flaw in the Pope's official prayer app exposed names, emails, and birth dates of over 719,000 users for six months before a fix.
An unauthenticated API flaw in the Pope's official prayer app exposed names, emails, and birth dates of over 719,000 users for six months before a fix.
AnMed shut most of its clinics after a malware disruption hit its network; emergency rooms stayed open and physician offices began reopening Tuesday.
Fudan University researchers built a flow battery using circulating zinc slurry instead of a fixed electrode, retaining 81.1% capacity after 5,500 cycles.
Antares Nuclear closed a $470 million Series C, seven weeks after its Mark-0 reactor reached criticality, to build microreactors for US military bases.
ESO's Very Large Telescope captured the clearest-ever image of Betelgeuse B, showing the long-sought companion is 2.6 to 3.1 times the sun's mass.
Researchers found 24,650 of 36,872 exposed server management interfaces disclose crackable password hashes before login, via a 2013 IPMI flaw still unpatched by Dell.
JFrog researchers turned a 16-year-old FFmpeg decoder bug, CVE-2026-8461, into working remote-code-execution exploits against Jellyfin and Nextcloud using one 50 KB video file.
University of Fribourg physicists used ultrafast laser pulses to briefly turn semiconducting tin telluride into a topological conductor, confirmed by time-resolved photoemission spectroscopy and published in Nature Physics.
A Scripps Research and La Jolla Institute for Immunology vaccine guided rhesus macaques to produce broadly neutralizing HIV antibodies, with human trials already underway.
STFC's 2.7% PPAN budget cut fully withdraws e-MERLIN funding, threatening Jodrell Bank's Lovell Telescope with closure.
Arista patched a maximum-severity command injection flaw in VeloCloud Orchestrator that attackers were already exploiting; CISA gave federal agencies until July 30 to fix it.
A maintenance-system bug stripped IP routes from Microsoft's West US datacenter on July 23, knocking out Teams, SharePoint, and Azure services for about five hours.