Search
Items tagged with: Cybersecurity
🙏 New Blog Post
The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.
What's exposed:
- Email addresses
- Names
- Country
- Date of birth (they call it "borned_date" lol)
- Account role (it's "PRAYER" for everyone, obviously)
Also found:
- Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
- Their verification emails fail their own domain's authentication requirements
Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.
Full writeup: bobdahacker.com/blog/click-to-…
#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity
Click to Pray, Click to Leak: The Pope's Official App Exposes 700,000+ User Emails
How I found that anyone can pull the email address, name, country, and date of birth of any of the 719,517 users on Click To Pray, the Pope's official prayer app, with a single GET request. Reported January 3rd. Still live six months later.bobdahacker.com
Microsoft “Digital Escorts” Could Expose Defense Dept. Data to Chinese Hackers — ProPublica
The Pentagon bans foreign citizens from accessing highly sensitive data, but Microsoft bypasses this by using engineers in China and elsewhere to remotely instruct American “escorts” who may lack expertise to identify malicious code.Doris Burke (ProPublica)
GovTech reports on the ITRC's H1 report:
"[ITRC]found that 1,029 data compromises generated 471 million breach notices in the first half of the year, with one incident — the breach involving Instructure’s Canvas platform — accounting for 275 million of those notices, or about 58 percent of the total."
govtech.com/security/instructu…
Direct link to ITRC report:
idtheftcenter.org/post/mega-br…
#databreach #cybersecurity #supplychain #Canvas #Instructure #EdTech
Instructure Incident Driving 58 Percent of Breach Notices in 2026
A new report has found that a single supply chain breach involving Instructure's Canvas platform generated more than half of all breach notices during the first six months of 2026.News Staff (GovTech)
#OpenAI says its #AI went #rogue and launched 'unprecedented' cyber-attack
source: bbc.com/news/articles/c3ek3gvd…
The #ChatGPT-maker said its agent - an AI #system which can operate alone after human instruction – was being tested in a controlled environment but, after finding weaknesses, was able to escape the test limits.They targeted #Hugging Face, one of the world's largest hubs for sharing AI models, gaining access to some internal company systems.
#news #cybersecurity #technology #test #security #economy #control #internet #problem #fail #hack #cyberattack #attack #skynet
A website to help selecting a #smartphone with a Google-free #Android
source: sustaphones.com
#news #google #googlefreeandroid #googlefree #android #phone #cybersecurity #security #surveillance #spy #tracking #help #choose #bigtech #technology #hardware #freedom #foss #floss #opensource #software #humanrights #economy
sustaphones
Website to recommend #tools to avoid supporting #ChatControl (available in EN, FR, DE and NL)
source: exitchatcontrol.org
#tool #utility #software #encryption #communication #eu #europe #law #surveillance #spy #chat #messenger #freedom #humanrights #democracy #politics #society #help #support #tutorial #knowhow #knowledge #security #cybersecurity #news
Exit Chat Control · Become Ungovernable
Looks like Hive Systems updated their password cracking table for 2026.
The only update is using 16Ă—RTX5090 Nvidia GPUs instead of 12. So the times got *slightly* smaller. Not much.
Attached is also the 2025 table so you can contrast and compare.
hivesystems.com/blog/are-your-…
Are Your Passwords in the Green?
The 2026 Hive Systems Password Table is here. This year's cracking rig is a rented 16x RTX 5090 fleet running against bcrypt, and was about 24% faster than last year.Corey Neskey (Hive Systems)
#Microsoft July 2026 #PatchTuesday fixes massive 570 flaws, 3 zero-days
We all know the APT numbers for #FancyBear and #CozyBear — #APT28 and #APT29. Both are attributed to Russian #intelligence. #APT1 through 27 are all from #China. Only the #EquationGroup doesn’t have an official APT number? Wake up, you sleeping sheep—we’re being thoroughly taken for a ride here. The Equation Group—run by the #NSA or #CIA — is probably the most dangerous group in the world, and yet it’s the one that doesn’t appear under any number on the #APT list? Who are you trying to fool here when it comes to #cybersecurity?
see: attack.mitre.org/groups/index.…
#news #conspiracy #snowden #surveillance #spy #usa #russia #thread #danger #warning #fail #security #cybersecurity #internet #online #hack #hacker #software #exploit #cyberattack #cybercrime #world #worldorder #censorship #deepstate
#meme #cybersecurity #chat #chatcontrol #security #eu# europe #politics #message #technology #spy #surveillance #problem #freedom #privacy #parliament #democracy #vote #ethics #future
VPNs aren’t just for privacy.
They’re essential cybersecurity tools that protect our personal data, help people to work or study remotely, and defend against cyber threats.
Restricting them makes everyone less safe – including children.
Sign and share the petition to protect VPN use in the UK ➡️ action.openrightsgroup.org/tel…
#SafeAndSecure #ProtectVPNs #vpn #cybersecurity #onlinesafety #privacy #ukpolitics #ukpol
Tell the Government: Protect VPN use in the UK
Take action! Protect VPN use in the UK VPNs help people to stay private and safe online. Young people use them to avoid harassment, or protect location data. Companies use them to make sure remote log-in to their networks are secure.Open Rights Group
Today we’ve joined over 20 organisations to urge the UK Government to protect children online without making the internet less secure by restricting VPNs.
Child safety and security aren’t competing objectives – we need both.
Read our letter ➡️ openrightsgroup.org/publicatio…
#SafeAndSecure #ProtectVPNs #vpn #cybersecurity #onlinesafety #privacy #ukpolitics #ukpol
Joint Letter: Protect VPNs
Dear Secretary of State, Protect children online without making the Internet less secure Protecting children online is an objective we all share.Open Rights Group
Ireland’s data centers consumed nearly as much electricity as every home in the country combined in 2025 — server farms gulped 23% of national power despite years of grid restrictions
Ireland’s data centers consumed 23% of the country’s electricity in 2025, rising 10% in one year despite restrictions on new grid connections.
tomshardware.com/tech-industry…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
Microsoft loses Brazilian court case after telling hacked Xbox user to re-purchase games — tech giant ordered to restore Xbox account with all games and pay $400 in damages
A Brazilian gamer who lost his Microsoft account and all his digital games has won a court order requiring the company to return them.
tomshardware.com/video-games/x…
#Tech #Technology #TechNews #AI #Gadgets #Software #Cybersecurity #Apple #Google #Microsoft #Startup #OpenSource #TomsHardware [Tom's Hardware]
New, by me: Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
krebsonsecurity.com/2026/07/fe…
#c2iris #irisc2 #cybersecurity #maga
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence compan…krebsonsecurity.com
NEW by me:
The “Anonymous” Tip System That Wasn’t: Three Months Later, Why Hasn’t Navigate360 Notified Anyone?
Note: there is a trigger warning at the top of this article as it contains sensitive material from tips submitted to and about students on what were supposed to be "anonymous" tiplines.
databreaches.net/2026/07/06/th…
This is the longest post I have ever done because people need to be more aware that this was the worst breach EVER in terms of highly sensitive personal information of students and their peers and families.
Great thanks to @douglevin for his comments and suggestions on the post.
@funnymonkey @mkeierleber @euroinfosec @jgreig @zackwhittaker @campuscodi @politico @dustinvolz
#databreach #anonymity #infosec #cybersecurity #Navigate360 #P3Campus #P3Global
Scattered Spider Suspect Extradited From Finland to US
A suspected member of the notorious Scattered Spider cybercrime group has been extradited from Finland to stand trial in the United States. Peter Stokes, 19, a dualwww.databreachtoday.com
China's AI Matches Anthropic in Cybersecurity, Causing Worry Over US Restrictions
#AIExportControls #OpenSourceAI #Anthropic #Cybersecurity #AICompetition
slashdot.org/story/26/06/28/19…
China's AI Matches Anthropic in Cybersecurity, Causing Worry Over US Restrictions - Slashdot
Chinese AI systems "have matched the performance of Anthropic's powerful model Mythos in some cybersecurity scenarios," reports the Wall Street Journal.slashdot.org
