In a sign that hackers hold nothing sacred, the Vatican was hacked, specifically, the Vatican's Click to Pray app.
Click to Pray offers Catholics daily prayers and papal updates, while also exposing their names, emails, passwords, and country of origin to hackers.
Cyber Security News has the details:
Analysts at DarkReading identified the exposure after ethical hacker BobDaHacker discovered an insecure direct object reference, or IDOR, vulnerability in January.
DarkReading independently tested the issue and reported that it remained accessible at the time of publication.
DarkReading said in a report shared with Cyber Security News (CSN) that the case is not a malware incident, but it highlights how a simple access-control failure can expose users to phishing, impersonation, and other targeted scams.
The hack required knowing a user ID, but all the user ids were created sequentially as new users were added, so it wasn't hard to start with 1 and work their way up to 700,000. And the lower numbers were administrators.

(I have to wonder if Pope Leo XIV had the number one spot.)
Now that hackers have all those emails and names, they can send phishing emails pretending to be the Vatican, which seem way more official, and try to get more information from users.
So, the big takeaway here is that from this point forward, no matter how many indulgences the pope offers you via email, don't give him your social security number.

Watch our latest video 👇
Source link
