logo

OWASP server blunder exposes decade of resumes

ID: 4fec8183-ec53-5bf4-aa29-4c4c4d76207f

STIX ID: report--4fec8183-ec53-5bf4-aa29-4c4c4d76207f

Feed Name: The Register (Security)

Threat Score
45/100

Date Published: 2024-04-02

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

OWASP discovered that a misconfigured MediaWiki server exposed member resumes (dating from ~2006–2014) containing names, emails, phone numbers, physical addresses and other PII. The foundation disabled directory browsing, removed the resumes, purged Cloudflare caches, requested removals from web archives, and is attempting to notify affected members; the exposed data could enable phishing, identity fraud, or other misuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.