[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fzzwtmsoP7KystsdUOMlurKpo9bNh6ASln1rsyK0EV7U":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"e9baa928-f9b5-4b58-8538-9756da531c8d","unprotected-api-endpoint-exposes-700k-vatican-app-users-pii","839cd7f2-9479-408e-94ea-9f2cfd1a0268","Unprotected API Endpoint Exposes 700K+ Vatican App Users' PII","The Vatican's official prayer app exposed personally identifiable information for over 700,000 users due to an API endpoint that required no authentication, meaning anyone with a browser could freely access sensitive data. This is a classic misconfigured API vulnerability — a growing attack surface as mobile and web applications increasingly rely on APIs to serve data. The exposed data (names, emails, location, account status) creates real risk for phishing, targeted scams, and religious profiling of users across the globe. The breach underscores that even mission-driven, non-commercial organizations must apply rigorous security controls to any internet-facing service handling personal data.","**Immediate actions:**\n- Audit all API endpoints immediately to verify that authentication and authorization controls are enforced before any data is returned.\n- Disable or firewall any publicly accessible endpoint that is not explicitly required to be public-facing.\n\n**Long-term improvements:**\n- Implement an API gateway with mandatory OAuth 2.0 or API key authentication for every endpoint that handles user data.\n- Establish a formal API inventory and include API security testing (e.g., OWASP API Security Top 10) as a required phase in the software development lifecycle.\n- Adopt a data minimization policy so that API responses only return the fields strictly necessary for the requesting function.\n\n**Detection measures:**\n- Deploy continuous API traffic monitoring to alert on anomalous bulk data retrieval or unauthenticated access patterns.\n- Schedule regular third-party penetration tests and automated DAST scans specifically targeting API endpoints before each major release.",[12,13,14,15,16,17,18,19,20,21,22],"NIST SP 800-53 AC-3 (Access Enforcement)","NIST SP 800-53 SC-8 (Transmission Confidentiality and Integrity)","NIST SP 800-53 SI-10 (Information Input Validation)","CIS Control 3: Data Protection","CIS Control 16: Application Software Security","OWASP API Security Top 10 – API1: Broken Object Level Authorization","OWASP API Security Top 10 – API2: Broken Authentication","GDPR Article 5(1)(f) – Integrity and Confidentiality","GDPR Article 25 – Data Protection by Design and by Default","GDPR Article 32 – Security of Processing","GDPR Article 33 – Notification of a Personal Data Breach","published","2026-07-24T14:20:40.678618+00:00","2026-07-24T14:20:40.51+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.darkreading.com\u002Fvulnerabilities-threats\u002Fvatican-official-prayer-app-leaks-700k-pii","vatican-s-official-prayer-app-leaks-700k-global-users-pii-25d4b4","Vatican's Official Prayer App Leaks 700K+ Global Users' PII",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":44,"name":45,"slug":46,"description":47,"color":48},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]