2 April 2024

OWASP Foundation discloses data breach due to Wiki web server misconfiguration


OWASP Foundation discloses data breach due to Wiki web server misconfiguration

OWASP Foundation, a US-based non-profit organization that supports the OWASP (The Open Worldwide Application Security Project) infrastructure and projects, has disclosed a security incident that affected member resumes.

The data breach, which occurred in late February 2024, was caused by a misconfiguration of OWASP’s old Wiki web server. The incident impacted the personally identifiable information (PII) of OWASP members from 2006 to around 2014 who provided their resumes as part of joining OWASP.

The affected data includes names, email addresses, phone numbers, physical addresses and other personal information, the foundation said in a short data breach notice.

In response to the breach, OWASP disabled directory browsing, reviewed the web server and Media Wiki configuration for other security issues, removed the resumes from the wiki site altogether, and cleared the CloudFlare cache to prevent further access. It has also requested that the information be deleted from the Web Archive.

OWASP said it “collected resumes as part of the early membership process, whereby members were required in the 2006 to 2014 era to show a connection to the OWASP community.” The organization assured that it no longer collects resumes as part of the membership process.

Back to the list

Latest Posts

Cyber Security Week in Review: August 30, 2024

Cyber Security Week in Review: August 30, 2024

Google addresses yet another Chrome zero-day, Russian hackers caught using commercial spyware to compromise victims, and more.
30 August 2024
US offers $2.5M reward for information on hacker linked to Angler exploit kit

US offers $2.5M reward for information on hacker linked to Angler exploit kit

Volodymyr Kadariya is believed to be a key player in a major international hacking operation.
29 August 2024
South Korean cyber espionage group exploits zero-day in WPS Office to install SpyGlace backdoor

South Korean cyber espionage group exploits zero-day in WPS Office to install SpyGlace backdoor

The vulnerability, tracked as CVE-2024-7262, has been exploited since at least February 2024.
29 August 2024