This is every bit as much a people problem as a technology problem. When I read the headline, I didn't even understand what there possibly was to breach at OWASP.
> OWASP collected resumes as part of the early membership process, whereby members were required in the 2006 to 2014 era to show a connection to the OWASP community. OWASP no longer collects resumes as part of the membership process.
Why did OWASP retain this information ten years after they stopped the practice?