Data Security , Privacy Pope’s prayer app leaks 700,000 user emails July 27, 2026 Share By SC Staff (Adobe Stock) The Click To Pray app, endorsed by the Pope and used by hundreds of thousands worldwide, was leaking user names and email addresses for months. An ethical hacker discovered the vulnerability six months ago and reported it, but received no response, as first reported by The Register. The security flaw, identified by ethical hacker BobDaHacker, stems from an Insecure Direct Object Reference (IDOR) bug. This allows anyone to access user data by simply incrementing a sequential user ID. The API endpoint GET https://api[.]clicktopray.org/user/users/{id} was found to return data for any account, not just the user's own. This exposed the personal information of all 719,517 registered accounts, including names, email addresses, countries, and dates of birth. The hacker noted that the lack of rate limiting means an attacker could easily scrape all user data. Furthermore, the signup endpoint returns a validation hash, allowing for account verification with any email address. This vulnerability creates a significant phishing risk, especially for less tech-savvy users who trust Vatican-related communications. The app's own verification emails also reportedly have authentication issues, making them appear similar to phishing attempts. Source: The Register SC Staff Related Data Security OnTrac parcel delivery company reports customer data breach SC Staff July 27, 2026 Bleeping Computer reports that the parcel delivery company OnTrac has experienced a data breach, potentially exposing customer personal details following a cyberattack on its corporate network. Data Security What Cloud, SaaS, and AI Data Security Actually Controls SC Media Editorial Intelligence, reviewed by Aparna Achanta July 24, 2026 The key is understanding where control assumptions break Encryption End-to-end encryption and the third round of the ‘going dark’ debate SC Staff July 23, 2026 A new paper analyzes the current controversies over end-to-end encryption (E2EE), which governments worldwide are seeking to limit for law enforcement and national security purposes. Related Events Cybercast Beyond the Hype: The Cybersecurity Trends CISOs are Keeping an Eye on in 2026 On-Demand Event Cybercast Beyond the data perimeter: Why next-generation DSPM is the foundation for modern data security On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Authenticity Block Cipher Ciphertext Cryptanalysis Cryptographic Algorithm or Hash Cyclic Redundancy Check (CRC) Data Aggregation Data Loss Prevention (DLP) Data Warehousing Digital Signature You can skip this ad in 5 seconds