Security flaw in Vatican’s ‘Click to Pray’ app leaves over 700,000 global users exposed — app has been leaking user data for over six months and still does
|
submitted by /u/kazu-qt [comments] |
|
submitted by /u/kazu-qt [comments] |
Russian state-backed hacker group Laundry Bear has been breaking into government and commercial networks for at least a year by exploiting a vulnerability in the Zimbra Collaboration Suite (ZCS) webmail platform. Laundry Bear (also known as Void Blizzard, CL-STA-1114, and TA488) has been running the campaign since July 2025, according to a joint advisory from…
This week, EFF joined Foxglove, Human Rights Watch, and 60 other organizations in writing to the UK’s Minister of State for Border Security and Asylum, Alex Norris, raising serious concern about the Home Office’s decision to deploy Facial Age Estimation (FAE) to assess asylum-seeking children from 2027. The letter points to four key concerns: Discrimination …
In my first weeks as Executive Director of EFF, I’ve been reminded every day how consequential this moment is in determining what kind of future we will have. We are on the edge. What each one of us steps up to do – with our expertise, energy, and resources – will determine whether our future…
This post is also available in: 繁體中文 (Chinese (Traditional)) Frontier AI is moving faster than most governance and response systems were designed to handle. The corporate landscape across the Japan and Asia-Pacific (JAPAC) region is facing an unprecedented regulatory and operational reckoning. The rise of hyper-autonomous ‘frontier’ AI models is pushing cyber security out of…
Every serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities that one person maintains in spare time. All of it carries the same label. A…
Healthcare finance software provider Craneware has disclosed a cyber incident that resulted in the theft of a significant volume of file names from its data environment. The company confirmed in a July 20 notice that it had identified a cybersecurity incident involving unauthorized access to some of its data environment. A “significant volume” of file…