50,000 sites backdoored through shoddy WordPress plugin

Jim 59

Unrelated, but there seems to be a widespread botnet attack on Wordpress blogs' "xmlrpc" feature in the last few days. People are reporting bots with up to 30,000 members trying to guess usernames and passwords. In the last 4 days my own low traffic blog has received 24,000 attempts from over 8000 bit IPs.

