I would imagine this is due to a Product manager vetoing time spent on Security Considerations.
On a more serious note, security breaches can happen to anyone. Might not be fair to assume it's the PMs negligence. In fact, I met some that really saw the value in security and cared to dedicate the resources on it even if that meant not shipping more features.