Three incidents highlight how weaknesses in application security, account protection, and operational resilience can expose personal information and interrupt essential services.


Vatican Prayer App Exposes Data of More Than 700,000 Users

The Vatican’s official Click to Pray app exposed names, email addresses, country information, account status, and administrative-role details through an API endpoint that required no authorization. The access-control flaw allowed sequential user records—including staff accounts—to be viewed and potentially collected at scale.

🔗 Read more on Dark Reading


Credential Stuffing Compromises Chick-fil-A Rewards Accounts

Attackers used credentials obtained from other sources to access Chick-fil-A One accounts during a credential-stuffing campaign. Exposed information could include names, contact details, membership and mobile-pay numbers, partial card numbers, account balances, addresses, and dates of birth, while some victims also had rewards taken from their accounts. Chick-fil-A logged out affected users, reset passwords, removed stored payment methods, and restored stolen balances.

🔗 Read more on SecurityWeek


Malware Disruption Forces AnMed to Close Clinics

Nonprofit health system AnMed reported a malware-related cybersecurity disruption affecting phone, internet, and other networked services across South Carolina and Georgia. The incident forced the closure of dozens of facilities and departments, including imaging, OB-GYN, primary care, and medical group offices, while urgent care services remained open.

🔗 Read more on The Record


HopeNet (HopeNetCISO.com) reviews a variety of security news sources so you do not have to! This list is curated specifically for churches, nonprofits, and other Organizations of Hope.

If this was shared with you and you would like to receive a copy directly to your email, please subscribe at HopeNetCISO.com. Thanks for reading!