Application security , Privacy Vatican’s ‘Click to Pray’ app leaks personal data of hundreds of thousands July 24, 2026 Share By SC Staff Phishing, mobile phone hacker or cyber scam concept. Password and login pass code in smartphone. Online security threat and fraud. Female scammer with cellphone and laptop. Bank account security. A popular Vatican website and mobile app, 'Click to Pray,' was found to be leaking the names and email addresses of hundreds of thousands of its users. The app, which provides daily prayers and papal content, is used globally. This vulnerability was discovered by a white hat hacker and confirmed by Dark Reading, based on information published by Dark Reading. A vulnerability known as an insecure direct object reference (IDOR) was discovered in the 'Click to Pray' application programming interface (API). This flaw allows any internet user to query a specific API endpoint and access personally identifying information (PII) of account holders, including employees of the Pope's Worldwide Prayer Network. Over 700,000 user accounts are exposed, with email addresses and names leaked in plaintext. The vulnerability requires no technical skill to exploit, only a browser. Attackers could use this data for mass emailing or social engineering schemes, leveraging users' faith. The Pope's Worldwide Prayer Network, which owns the app developed by La Machi, has not yet responded to requests for comment. This incident highlights a common type of vulnerability, broken access control, which remains prevalent across various industries and company sizes, based on information published by Dark Reading. Source: Dark Reading SC Staff Related Application security Man charged for using phone’s ‘duress’ password to wipe data SC Staff July 24, 2026 The U.S. Justice Department is prosecuting an American man for allegedly providing U.S. border authorities with a passcode that wiped the contents of his phone, a case believed to be the first of its kind in the United States where federal prosecutors have charged someone for the alleged destruction of data using a "duress" password, as first reported by TechCrunch. Application security macOS Gatekeeper vulnerability allows app replacement SC Staff July 24, 2026 As detailed in The Register, security researchers uncovered a vulnerability in Apple's macOS Gatekeeper security feature that could allow malicious actors to replace legitimate applications with harmful versions. Application security Millions of vehicles vulnerable to Bluetooth car theft attacks SC Staff July 23, 2026 Millions of vehicles equipped with dealer-installed KARR and SWDS security systems are susceptible to Bluetooth-based attacks that could allow unauthorized access or prevent vehicles from starting. Related Events Cybercast Bridging the Gap from CISO-Developed Tools to Black Hat Hype: What AI Security Leaders Should Watch Next On-Demand Event Cybercast Protecting Application User Data for Better Privacy, Governance, and Compliance On-Demand Event Cybercast The Next Evolution of Application Security: AI- Accelerated DevSecOps On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Browser Certificate-Based Authentication Client Common Gateway Interface (CGI) Cookie DLL Injection Dynamic Link Library Geolocation Identity Theft Inference Attack You can skip this ad in 5 seconds