Vatican's Click to Pray App Leaked 700,000+ Users' Data for Six Months Before Being Quietly Fixed
An unauthenticated API flaw in the Pope's official prayer app exposed names, emails, and birth dates of over 719,000 users for six months before a fix.
Signal
36 articles covering "data-breach"
An unauthenticated API flaw in the Pope's official prayer app exposed names, emails, and birth dates of over 719,000 users for six months before a fix.
AnMed shut most of its clinics after a malware disruption hit its network; emergency rooms stayed open and physician offices began reopening Tuesday.
A breach at gig-work platform Paidwork exposed names, bank details, and bcrypt-hashed passwords for over 23 million users, per Have I Been Pwned.
Hugging Face disclosed that an autonomous AI agent system breached its data-processing pipeline over a weekend, harvesting credentials before defenders turned to a self-hosted open-weight model to analyze the attack.
A 42-attorney-general coalition settled bankruptcy claims against 23andMe for $18 million over the 2023 breach of 6.9 million genetic profiles, days after a court barred California from separately pursuing damages.
Accenture confirmed a security incident after a hacker known as "888" listed 35GB of alleged source code, RSA/SSH keys, and Azure access tokens for sale on a cybercrime forum.
AssuranceAmerica is notifying 6.99 million people that hackers stole driver's license numbers and insurance records after a March cyberattack on an employee account.
A vulnerability in third-party email software let attackers reach up to 14.2 million KDDI ISP logins; a later update put confirmed exposure at 12.23 million addresses and 7.61 million passwords.
Aflac Life Insurance Japan says attackers accessed its policyholder portal between June 15 and 25, exposing personal data on roughly 4.38 million customers and agents.
A cyberattack on the UN World Food Programme's Palestine registration app exposed personal data of about 600,000 Gaza households, drawing criticism over a 17-day notification delay.
Cybernews researchers found an unsecured Elasticsearch cluster holding 24 billion records compiled from 36 sources, mostly infostealer logs with plaintext passwords.
Attackers abused a compromised legacy Klue credential to mint Salesforce OAuth tokens and pull CRM records over roughly 24 hours. Salesforce disabled the Battlecards app on June 17.