Skip to main content

Search

Items tagged with: InfoSec


🙏 New Blog Post

The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.

What's exposed:

  • Email addresses
  • Names
  • Country
  • Date of birth (they call it "borned_date" lol)
  • Account role (it's "PRAYER" for everyone, obviously)

Also found:

  • Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
  • Their verification emails fail their own domain's authentication requirements

Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.

Full writeup: bobdahacker.com/blog/click-to-…

#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity


NEW by me:

The “Anonymous” Tip System That Wasn’t: Three Months Later, Why Hasn’t Navigate360 Notified Anyone?

Note: there is a trigger warning at the top of this article as it contains sensitive material from tips submitted to and about students on what were supposed to be "anonymous" tiplines.

databreaches.net/2026/07/06/th…

This is the longest post I have ever done because people need to be more aware that this was the worst breach EVER in terms of highly sensitive personal information of students and their peers and families.

Great thanks to @douglevin for his comments and suggestions on the post.

@funnymonkey @mkeierleber @euroinfosec @jgreig @zackwhittaker @campuscodi @politico @dustinvolz

#databreach #anonymity #infosec #cybersecurity #Navigate360 #P3Campus #P3Global


RE: eldritch.cafe/@HauntedOwlbear/…

Seriously infosec ppl we actually have no excuse. Here, take my collection of places to find free, public domain images, you'll discover some amazing art:

#infosec #noAI


RE: infosec.exchange/@mttaggart/11…

This is a really important read for understanding both what's under the hood with LLMs, but also why it is impossible to secure any #LLM.

In the thread, I posted a couple of extra links to experts explaining that last sentence better than I can. But read the article Taggart linked first.

#AI #TulipMania #infosec


This is a masterful demonstration of the unsecurable nature of LLMs, and how prompt injection by dedicated humans who know how to write will always win.

role-confusion.github.io/