::Trend Micro Threat Resource Center::

13 June 2011

Cyber Attack Compromises 18 Million WordPress Blogs

Bad news for just about every blogger out there. It seems WordPress, an extremely popular suite of tools for powering blogs, has been the victim of a cyber attack. Automattic, the company that owns WordPress, admitted to the attack this morning and noted that it may have left over 18 million blogs vulnerable.

WordPress founder Matt Mullenweg writes “Tough note to communicate today: Automattic had a low-level (root) break-in to several of our servers, and potentially anything on those servers could have been revealed.”

Mullenweg continues “We have been diligently reviewing logs and records about the break-in to determine the extent of the information exposed, and re-securing avenues used to gain access. We presume our source code was exposed and copied. While much of our code is Open Source, there are sensitive bits of our and our partners’ code. Beyond that, however, it appears information disclosed was limited.”

Analysts, including Alexia Tsosis of TechCrunch, have suggested that Mullenweg is downplaying the issue. She indicates that everything from Facebook and Twitter passwords to API keys could have been leaked.

So what does this mean to you? Probably nothing. There is a lot of information out there and the chances of your passwords being nabbed are slim. Still, it is about time you get them changed right? You’ve been using the same two passwords since High School and if you haven’t formed that band by now you probably are never going to. Wait, maybe that’s just me.