Normale Ansicht

Received yesterday — 27. Juli 2026

Datenpanne bei offizieller Gebets-App des Papstes: 700.000 Nutzerdaten landen im Netz

27. Juli 2026 um 12:00
Eine Sicherheitsforscherin hat eine Schwachstelle in Click to Pray, der offiziellen Gebets-App des Papstes, entdeckt. Über Monate hinweg ließen sich Daten der 700.000 Nutzer:innen abrufen. Eine Reaktion der Betreiber gibt es bis heute nicht.weiterlesen auf t3n.de

Linux Kernel verzeichnet 432 CVEs in nur zwei Tagen

Von:MK
27. Juli 2026 um 07:00

Innerhalb von zwei Tagen erschienen 432 neue Linux Kernel Einträge. Die hohe Zahl sorgt für Diskussionen in der Open Source Gemeinschaft. Experten warnen vor wachsendem Aufwand. Sicherheitsteams stoßen zunehmend an ihre Grenzen. Jede gemeldete Schwachstelle muss geprüft und bewertet werden. Die steigende Menge erschwert sinnvolle Priorisierungen erheblich. Als mögliche Lösung gilt eine stärkere Automatisierung. Künstliche […]

Der Beitrag Linux Kernel verzeichnet 432 CVEs in nur zwei Tagen erschien zuerst auf fosstopia.

Open Secure AI Alliance: Nvidia, Microsoft, Adobe und mehr wollen für mehr KI-Sicherheit sorgen

27. Juli 2026 um 14:30
Nvidia hat bekannt gegeben, dass man mit zahlreichen anderen Unternehmen die sogenannte Open Secure AI Alliance gegründet hat. Zu den weiteren Mitgliedern zählen beispielsweise auch noch...

Zum Beitrag: Open Secure AI Alliance: Nvidia, Microsoft, Adobe und mehr wollen für mehr KI-Sicherheit sorgen

Wo du uns folgen kannst: Facebook, Reddit, Google News, X, Threads

Received before yesterday

Security flaw in Vatican’s ‘Click to Pray’ app leaves over 700,000 global users exposed — app has been leaking user data for over six months and still does

Click To Pray, the official prayer app of the Pope’s Worldwide Prayer Network, was found to have zero security by a security researcher. According to BobDaHacker, they discovered in January 2026 that the Vatican-linked app had zero security, allowing anyone to access user data through the API endpoint by simply typing in user IDs. They emailed nine individuals about the vulnerabilities as soon as they discovered them but received no responses and saw no changes for six months.

The information that anyone could get from the Click To Pray app’s database included first and last names, email addresses, and birthdates, among other information. You may not think this is much, but getting names and email addresses is more than enough for bad actors to start sending phishing emails to vulnerable users. BobDaHacker also pointed out that most of the app's users are likely older people who aren’t tech-savvy, so any enterprising scammer could tap into the app for a literal treasure trove of email addresses.

It was also easy to get the complete list automatically. The user ID assigned to new accounts is sequential, and since there’s no rate limiting for the API, all it takes is one GET request per user to capture all that information. Aside from this, the validation_hash used to verify the validity of an account signup is also stored in the clear, meaning anyone with access to the API can verify an account by opening their inbox. The email also had security issues that make it look like a phishing email, even if it’s legitimate.

You may think that a prayer app shouldn’t be much of a target for cybercriminals, especially as this has a small install base compared to the 16 billion accounts exposed in one of the largest data breaches in history. But the fact that it had almost 720,000 accounts as of July 2026 meant that there’s a lot of possible targets within that database. Even if just 1% of these users respond to an enterprising cybercriminal who harvested their email addresses from the app, that’s more than 7,000 different individuals who could lose money because of this leak.

BobDaHacker waited for six months for a response, but, unfortunately, no one related to the app responded to their concerns. Because of this, they contacted Nate Neslon, a security journalist for Dark Reading (who similarly received crickets after contacting them), who published a story about it. It was only after the news went live that the app’s security lapses were fixed, even if BobDaHacker wasn’t, at the very least, acknowledged by the makers of the app. Hopefully, no other hackers were aware of the weaknesses of the Click To Pray app.

Tokn: ein quelloffener 2FA-Authenticator für Android ohne Cloud-Zwang

Von:caschy
25. Juli 2026 um 19:30
Wer im Netz auf Sicherheit bedacht ist, kommt um Zwei-Faktor-Authentisierung (2FA) nicht herum. Der Markt an Authenticator-Apps ist groß, doch viele namhafte Lösungen drängen Nutzer zunehmend...

Zum Beitrag: Tokn: ein quelloffener 2FA-Authenticator für Android ohne Cloud-Zwang

Wo du uns folgen kannst: Facebook, Reddit, Google News, X, Threads

Claude Opus 5: Neues Anthropic-Modell soll so gut wie Fable 5 sein, aber nur die Hälfte kosten

24. Juli 2026 um 22:17
Anthropic hat mit Claude Opus 5 ein neues KI-Modell an den Start gebracht, das Fable 5 in Sachen Performance die Stirn bieten können soll. Nur bei der Cybersicherheit ist noch Luft nach oben. Nutzer:innen zahlen dafür aber nur die Hälfte der KI-Token-Kosten.weiterlesen auf t3n.de

Passkeys ziehen bei GMX und WEB.DE ein: Passwortloser Login für Nutzer

Von:caschy
24. Juli 2026 um 14:00
Die Mail-Anbieter GMX und WEB.DE schalten ab sofort den Login per Passkey für ihre rund 38 Millionen Nutzer frei. Damit lässt sich das E-Mail-Postfach im Browser...

Zum Beitrag: Passkeys ziehen bei GMX und WEB.DE ein: Passwortloser Login für Nutzer

Wo du uns folgen kannst: Facebook, Reddit, Google News, X, Threads

FRITZ!OS 8.40 bringt nativen DNS-Filter gegen Werbung, Tracker und Malware

Von:caschy
24. Juli 2026 um 11:30
Es ist vermutlich etwas untergegangen, deswegen erwähne ich es noch einmal dediziert. FRITZ! bohrt die FRITZ!Box mit FRITZ!OS 8.40 um ein mächtiges Sicherheits-Feature auf: Ab dieser...

Zum Beitrag: FRITZ!OS 8.40 bringt nativen DNS-Filter gegen Werbung, Tracker und Malware

Wo du uns folgen kannst: Facebook, Reddit, Google News, X, Threads

Support-Ende für OneDrive unter Windows 10 konkretisiert

Von:caschy
24. Juli 2026 um 10:30
  Microsoft hat die Pläne zum Support-Ende der OneDrive-Synchronisierungs-App unter Windows 10 präzisiert und ein konkretes Datum genannt. Ab dem 15. August 2026 stellt das Unternehmen...

Zum Beitrag: Support-Ende für OneDrive unter Windows 10 konkretisiert

Wo du uns folgen kannst: Facebook, Reddit, Google News, X, Threads

Google testet Konto-Wiederherstellung per Selfie-Video

Von:caschy
23. Juli 2026 um 12:30
Google bohrt seine Sicherheitsoptionen weiter auf und bringt eine neue Methode zur Kontowiederherstellung an den Start: Nutzer können sich künftig per Selfie-Video ausweisen, falls das Passwort...

Zum Beitrag: Google testet Konto-Wiederherstellung per Selfie-Video

Wo du uns folgen kannst: Facebook, Reddit, Google News, X, Threads

💾

Ring bringt zwei neue Sicherheitskameras: Outdoor Camera (2. Generation) und Peephole Camera 2K

23. Juli 2026 um 10:00
Ring erweitert Sicherheitskamera-Portfolio um neue Modelle mit „Retinal 2K“, wie die Marke von Amazon es selbst nennt. Mit dabei sind jedenfalls bald die neue Ring Outdoor...

Zum Beitrag: Ring bringt zwei neue Sicherheitskameras: Outdoor Camera (2. Generation) und Peephole Camera 2K

Wo du uns folgen kannst: Facebook, Reddit, Google News, X, Threads

Wenn die Sandbox zur Falle wird: So können KI-Agenten unbemerkt ausbrechen

21. Juli 2026 um 13:30
Eigentlich sollen Sandboxes die Sicherheit beim Umgang mit KI-Agenten erhöhen. KI-Forscher:innen haben allerdings herausgefunden, dass sich die Testumgebungen durchbrechen lassen – ohne dabei eine Regel zu missachten.weiterlesen auf t3n.de

Google ändert Backup-Richtlinien: Android-Sicherungen kosten bald Speicherplatz

Von:caschy
19. Juli 2026 um 12:00
Bislang war das Sichern von Android-Geräten in der Google-Cloud ein recht entspanntes Thema. Abseits von Fotos, Videos und MMS-Medien belegten Geräteeinstellungen, SMS-Verläufe und App-Daten keinen Speicherplatz auf dem persönlichen Google-Konto. Das ändert sich nun. Google hat eine Anpassung der Speicherplatz-Richtlinien...

Zum Beitrag: Google ändert Backup-Richtlinien: Android-Sicherungen kosten bald Speicherplatz

Wo du uns folgen kannst: Facebook, Reddit, Google News, X, Threads

KeeForge für iOS: Open-Source-KeePass-Client mit neuen Funktionen

Von:caschy
19. Juli 2026 um 09:00
KeeForge ist ein schlanker Open-Source-Client für KeePass unter iOS, der komplett ohne Tracker, Werbung oder Abonnements auskommt. Vorgestellt habe ich euch das Projekt ausführlich in diesem Beitrag. Die App ist GPL-3.0-lizenziert und erlaubt euch die Verwaltung eurer verschlüsselten Passwörtertresore im...

Zum Beitrag: KeeForge für iOS: Open-Source-KeePass-Client mit neuen Funktionen

Wo du uns folgen kannst: Facebook, Reddit, Google News, X, Threads

Florida man arrested after allegedly stealing $220,000 in crypto using malware hidden in Steam Games — 8,000 devices infected

17. Juli 2026 um 16:43

Federal agents arrested 21-year-old Zyaire Dontaevious Zamarion Wilkins of North Lauderdale, Florida, on Tuesday and charged him with conspiracy to obtain information by computer for private financial gain, according to a 15-page criminal complaint first reported by WPLG Local 10. The FBI alleges Wilkins helped run an operation that embedded malware in eight video games, infected around 8,000 devices, and stole at least $220,000 from roughly 80 cryptocurrency wallets between May 2024 and February 2026. Investigators put a name to the scheme by following stolen Bitcoin to more than 150 gift cards, most of them spent on Uber Eats.

The complaint identifies the distribution channel only as a "popular digital distribution software company," but the games it lists, including BlockBlasters, Dashverse, Lunara, and PirateFi, match the titles named when the FBI began seeking victims of infected Steam games in March. The case is being prosecuted in Seattle federal court, near Valve's headquarters in Bellevue, Washington, and Wilkins' arrest is the first publicly reported in the investigation.

Wilkins allegedly financed and marketed the malware rather than writing it, with Local 10 reporting that agents had already searched the home of the unidentified developer who built the programs, and that Signal chats seized there tied Wilkins, operating under the handle Sibel.eth, to a $10,000 purchase of a remote access trojan and to discussions about tricking victims into approving transactions that emptied their wallets. That developer isn't named in the complaint and doesn't appear to have been charged.

The conspirators promoted the games on Discord, Telegram, X, and LinkedIn, and used bots to find users with large cryptocurrency holdings and message them directly, according to the complaint. Roughly 80 wallets were drained from 8,000 infections, a hit rate of about 1% consistent with that targeted approach. ZachXBT and vx-underground estimated BlockBlasters alone took more than $150,000 from between 261 and 478 victims, including $32,000 in donated cancer treatment funds taken from a Twitch streamer in September 2025.

Payments from the scheme's Bitcoin wallet went to Bitrefill, a gift card service, where the 150-plus cards were purchased, agents said. A subpoena to Uber matched the cards to an account with deliveries at Wilkins' family home and his addresses at the University of West Florida. When agents searched the North Lauderdale house a week before the arrest, they seized several devices and three cryptocurrency wallet seed phrases, one belonging to a Monero wallet. Wilkins' transaction history showed $382,000 in cryptocurrency sent or received, per the complaint.

Wilkins faces up to 10 years in prison if convicted and was scheduled to appear in Fort Lauderdale federal court on July 15. Valve, whose storefront has seen a steady run of malware incidents over the past two years, including the Chemia Early Access game that shipped with three malware strains, hadn't responded to Local 10's request for comment as of publication.

Robot vacuum flaw lets one stolen certificate run root commands on other Shark robovacs in the same AWS region — unpatched flaw exposes live camera feeds, stored home maps, and Wi-Fi credentials

17. Juli 2026 um 12:00

A security researcher has published a method for lifting the client certificate off a Shark robot vacuum and using it to run root commands on other Shark vacuums across the same Amazon Web Services region, exposing live camera feeds, stored home maps, and Wi-Fi credentials held in plaintext. The researcher, who publishes under the handle tokay0, published the technique on Monday and says he first reported it to SharkNinja on March 1. As of the time of writing, the flaw is still unpatched, requiring a fix that sits entirely on SharkNinja's side of the cloud rather than on the robot.

The problem is an over-permissive AWS IoT policy. The certificate that a Shark vacuum uses to authenticate to Amazon's cloud broker was never restricted to the device carrying it, so a certificate pulled from one unit can subscribe to fleet-wide traffic and publish commands addressed to any device the broker serves. Those commands travel in an ordinary field called Exec_Command inside the per-device state document AWS keeps in the cloud, and a management daemon on the vacuum passes anything under 1,000 bytes from it to a shell.

The researcher tested the technique only on units he bought himself, including a cross-model reverse shell on an AV1102ARUS Shark IQ Robot Vacuum XL, which he then used to pull a live feed off that robot's onboard camera. Watching a single AWS region for 24 hours, he counted 1,517,605 unique Shark serial numbers, of which 673,816, or 44%, replied to a command probe. Those are devices observed responding, not devices he tested or compromised. Certificates are pinned to their AWS region, so a key lifted in one region only reaches devices in that region.

tokay0 says SharkNinja acknowledged his report on March 12, told him on April 27 that it was under review, and on July 3 promised a completion date by July 10 that never arrived. He also says the company downplayed the severity and questioned whether a CVE was warranted, despite a published disclosure policy that commits SharkNinja to "provide regular updates until the reported vulnerability is resolved." The company had posted nothing on the flaw as of July 16.

Remediation in this scenario doesn’t require a firmware update. Per Amazon, a non-compliant IoT policy is fixed by pushing a scoped version inside the operator's own AWS account until SharkNinja rescopes the policy or reissues the certificates.

SharkNinja's timeline is pretty similar to a vulnerability we saw with DJI Romo vacuums back in February, whereby an authorization flaw exposed roughly 6,700 vacuums, handing out camera feeds, audio, and floor plans; DJI patched it within weeks, and the researcher who found it later collected a $30,000 bounty. Cloud-side failures, where a backend fails to scope device access, have driven a run of robot-vacuum breaches and fueled interest in fully offline designs that keep mapping and camera data off any vendor cloud.

Enpass: Passwort-Risiken direkt beim Entsperren im Blick

Von:caschy
15. Juli 2026 um 15:30
Kurzer Hinweis für alle, die ihre Passwörter mit Enpass verwalten: Die Entwickler rollen aktuell ein Update für die mobilen Apps auf iOS und Android aus. Im Fokus stehen dabei eine komplett runderneuerte Startseite und eine neue Metrik namens Security Score....

Zum Beitrag: Enpass: Passwort-Risiken direkt beim Entsperren im Blick

Wo du uns folgen kannst: Facebook, Reddit, Google News, X, Threads

❌