Anyone know any details? From the description, this sounds like the kind of thing where there's an INPUT TYPE=HIDDEN or a cookie with an integer userid, and the attacker just rotated it and crawled profile pages. Sucks, but not the end of the world.
I'd definitely like to know, since the WaPo guys use a lot of django. If (big if, I don't acutally know) the jobs site was built on django, and if they could figure out how it was compromised it would be beneficial for the wider django community to know. I hope they share when the dust settles.
I used to be one of the WaPo Django guys. Jobs was a separate team on entirely different technology stack on different hardware, though probably in the same data center. I know they happened to use Java (and probably still do) but have no more info (nor did I want any - c'mon, Java).