Datenpanne bei offizieller Gebets-App des Papstes: 700.000 Nutzerdaten landen im Netz


Innerhalb von zwei Tagen erschienen 432 neue Linux Kernel Einträge. Die hohe Zahl sorgt für Diskussionen in der Open Source Gemeinschaft. Experten warnen vor wachsendem Aufwand. Sicherheitsteams stoßen zunehmend an ihre Grenzen. Jede gemeldete Schwachstelle muss geprüft und bewertet werden. Die steigende Menge erschwert sinnvolle Priorisierungen erheblich. Als mögliche Lösung gilt eine stärkere Automatisierung. Künstliche […]
Der Beitrag Linux Kernel verzeichnet 432 CVEs in nur zwei Tagen erschien zuerst auf fosstopia.
Zum Beitrag: Open Secure AI Alliance: Nvidia, Microsoft, Adobe und mehr wollen für mehr KI-Sicherheit sorgen
Wo du uns folgen kannst:
Facebook, Reddit, Google News, X, Threads
Click To Pray, the official prayer app of the Pope’s Worldwide Prayer Network, was found to have zero security by a security researcher. According to BobDaHacker, they discovered in January 2026 that the Vatican-linked app had zero security, allowing anyone to access user data through the API endpoint by simply typing in user IDs. They emailed nine individuals about the vulnerabilities as soon as they discovered them but received no responses and saw no changes for six months.
The information that anyone could get from the Click To Pray app’s database included first and last names, email addresses, and birthdates, among other information. You may not think this is much, but getting names and email addresses is more than enough for bad actors to start sending phishing emails to vulnerable users. BobDaHacker also pointed out that most of the app's users are likely older people who aren’t tech-savvy, so any enterprising scammer could tap into the app for a literal treasure trove of email addresses.
It was also easy to get the complete list automatically. The user ID assigned to new accounts is sequential, and since there’s no rate limiting for the API, all it takes is one GET request per user to capture all that information. Aside from this, the validation_hash used to verify the validity of an account signup is also stored in the clear, meaning anyone with access to the API can verify an account by opening their inbox. The email also had security issues that make it look like a phishing email, even if it’s legitimate.
You may think that a prayer app shouldn’t be much of a target for cybercriminals, especially as this has a small install base compared to the 16 billion accounts exposed in one of the largest data breaches in history. But the fact that it had almost 720,000 accounts as of July 2026 meant that there’s a lot of possible targets within that database. Even if just 1% of these users respond to an enterprising cybercriminal who harvested their email addresses from the app, that’s more than 7,000 different individuals who could lose money because of this leak.
BobDaHacker waited for six months for a response, but, unfortunately, no one related to the app responded to their concerns. Because of this, they contacted Nate Neslon, a security journalist for Dark Reading (who similarly received crickets after contacting them), who published a story about it. It was only after the news went live that the app’s security lapses were fixed, even if BobDaHacker wasn’t, at the very least, acknowledged by the makers of the app. Hopefully, no other hackers were aware of the weaknesses of the Click To Pray app.
Zum Beitrag: Tokn: ein quelloffener 2FA-Authenticator für Android ohne Cloud-Zwang
Wo du uns folgen kannst:
Facebook, Reddit, Google News, X, Threads

Zum Beitrag: Passkeys ziehen bei GMX und WEB.DE ein: Passwortloser Login für Nutzer
Wo du uns folgen kannst:
Facebook, Reddit, Google News, X, Threads
Zum Beitrag: FRITZ!OS 8.40 bringt nativen DNS-Filter gegen Werbung, Tracker und Malware
Wo du uns folgen kannst:
Facebook, Reddit, Google News, X, Threads
Zum Beitrag: Support-Ende für OneDrive unter Windows 10 konkretisiert
Wo du uns folgen kannst:
Facebook, Reddit, Google News, X, Threads
Zum Beitrag: Google testet Konto-Wiederherstellung per Selfie-Video
Wo du uns folgen kannst:
Facebook, Reddit, Google News, X, Threads
Zum Beitrag: Ring bringt zwei neue Sicherheitskameras: Outdoor Camera (2. Generation) und Peephole Camera 2K
Wo du uns folgen kannst:
Facebook, Reddit, Google News, X, Threads

Zum Beitrag: Google ändert Backup-Richtlinien: Android-Sicherungen kosten bald Speicherplatz
Wo du uns folgen kannst:
Facebook, Reddit, Google News, X, Threads
Zum Beitrag: KeeForge für iOS: Open-Source-KeePass-Client mit neuen Funktionen
Wo du uns folgen kannst:
Facebook, Reddit, Google News, X, Threads
Federal agents arrested 21-year-old Zyaire Dontaevious Zamarion Wilkins of North Lauderdale, Florida, on Tuesday and charged him with conspiracy to obtain information by computer for private financial gain, according to a 15-page criminal complaint first reported by WPLG Local 10. The FBI alleges Wilkins helped run an operation that embedded malware in eight video games, infected around 8,000 devices, and stole at least $220,000 from roughly 80 cryptocurrency wallets between May 2024 and February 2026. Investigators put a name to the scheme by following stolen Bitcoin to more than 150 gift cards, most of them spent on Uber Eats.
The complaint identifies the distribution channel only as a "popular digital distribution software company," but the games it lists, including BlockBlasters, Dashverse, Lunara, and PirateFi, match the titles named when the FBI began seeking victims of infected Steam games in March. The case is being prosecuted in Seattle federal court, near Valve's headquarters in Bellevue, Washington, and Wilkins' arrest is the first publicly reported in the investigation.
Wilkins allegedly financed and marketed the malware rather than writing it, with Local 10 reporting that agents had already searched the home of the unidentified developer who built the programs, and that Signal chats seized there tied Wilkins, operating under the handle Sibel.eth, to a $10,000 purchase of a remote access trojan and to discussions about tricking victims into approving transactions that emptied their wallets. That developer isn't named in the complaint and doesn't appear to have been charged.
The conspirators promoted the games on Discord, Telegram, X, and LinkedIn, and used bots to find users with large cryptocurrency holdings and message them directly, according to the complaint. Roughly 80 wallets were drained from 8,000 infections, a hit rate of about 1% consistent with that targeted approach. ZachXBT and vx-underground estimated BlockBlasters alone took more than $150,000 from between 261 and 478 victims, including $32,000 in donated cancer treatment funds taken from a Twitch streamer in September 2025.
Payments from the scheme's Bitcoin wallet went to Bitrefill, a gift card service, where the 150-plus cards were purchased, agents said. A subpoena to Uber matched the cards to an account with deliveries at Wilkins' family home and his addresses at the University of West Florida. When agents searched the North Lauderdale house a week before the arrest, they seized several devices and three cryptocurrency wallet seed phrases, one belonging to a Monero wallet. Wilkins' transaction history showed $382,000 in cryptocurrency sent or received, per the complaint.
Wilkins faces up to 10 years in prison if convicted and was scheduled to appear in Fort Lauderdale federal court on July 15. Valve, whose storefront has seen a steady run of malware incidents over the past two years, including the Chemia Early Access game that shipped with three malware strains, hadn't responded to Local 10's request for comment as of publication.
A security researcher has published a method for lifting the client certificate off a Shark robot vacuum and using it to run root commands on other Shark vacuums across the same Amazon Web Services region, exposing live camera feeds, stored home maps, and Wi-Fi credentials held in plaintext. The researcher, who publishes under the handle tokay0, published the technique on Monday and says he first reported it to SharkNinja on March 1. As of the time of writing, the flaw is still unpatched, requiring a fix that sits entirely on SharkNinja's side of the cloud rather than on the robot.
The problem is an over-permissive AWS IoT policy. The certificate that a Shark vacuum uses to authenticate to Amazon's cloud broker was never restricted to the device carrying it, so a certificate pulled from one unit can subscribe to fleet-wide traffic and publish commands addressed to any device the broker serves. Those commands travel in an ordinary field called Exec_Command inside the per-device state document AWS keeps in the cloud, and a management daemon on the vacuum passes anything under 1,000 bytes from it to a shell.
The researcher tested the technique only on units he bought himself, including a cross-model reverse shell on an AV1102ARUS Shark IQ Robot Vacuum XL, which he then used to pull a live feed off that robot's onboard camera. Watching a single AWS region for 24 hours, he counted 1,517,605 unique Shark serial numbers, of which 673,816, or 44%, replied to a command probe. Those are devices observed responding, not devices he tested or compromised. Certificates are pinned to their AWS region, so a key lifted in one region only reaches devices in that region.
tokay0 says SharkNinja acknowledged his report on March 12, told him on April 27 that it was under review, and on July 3 promised a completion date by July 10 that never arrived. He also says the company downplayed the severity and questioned whether a CVE was warranted, despite a published disclosure policy that commits SharkNinja to "provide regular updates until the reported vulnerability is resolved." The company had posted nothing on the flaw as of July 16.
Remediation in this scenario doesn’t require a firmware update. Per Amazon, a non-compliant IoT policy is fixed by pushing a scoped version inside the operator's own AWS account until SharkNinja rescopes the policy or reissues the certificates.
SharkNinja's timeline is pretty similar to a vulnerability we saw with DJI Romo vacuums back in February, whereby an authorization flaw exposed roughly 6,700 vacuums, handing out camera feeds, audio, and floor plans; DJI patched it within weeks, and the researcher who found it later collected a $30,000 bounty. Cloud-side failures, where a backend fails to scope device access, have driven a run of robot-vacuum breaches and fueled interest in fully offline designs that keep mapping and camera data off any vendor cloud.
Zum Beitrag: Enpass: Passwort-Risiken direkt beim Entsperren im Blick
Wo du uns folgen kannst:
Facebook, Reddit, Google News, X, Threads