Skip to main content

April WordPress hack the latest in long line of similar attacks

WordPress LogoAutomattic, the purveyor of WordPress, has suffered a recent security breach that could present to significant security risk for WordPress-powered sites.

“Automattic had a low-level (root) break-in to several of our servers, and potentially anything on those servers could have been revealed,” WordPress founder Matt Mullenweg explained on the WordPress blog, on Wednesday. Mullenweg goes on to write that WordPress is reviewing the logs and suspects its source code was copied. The company has little advice for users, other than to strengthen their passwords. Not only is the WordPress blog hosting affected, but many of Automattic’s other services are potentially at-risk.

Recommended Videos

The consequences of this attack by hackers will definitely be felt by the major VIP members of the WordPress service such as NASA, CBS and The New York Times. Alexia Tsosis from TechCrunch (also a VIP member) says “VIP customers are all on ‘code red’ and in the process of changing all the passwords/API keys they’ve left in the source code.”  Tsosis says that Automattic is downplaying the potential severity of this attack.

There have been a bevy of hack attacks occurring lately against big name companies, such as the DDoS attacks against Sony PlayStation by Anonymous, as well as the EMC breach, Epsilon, and lets not forget that this isn’t the first time WordPress has been attacked.

WordPress was hit hard in 2009 when hidden admin accounts were creating back doors. Just last month, WordPress also suffered a huge DDoS attack, affecting 10 percent of its hosted sites. Let’s remember that this blog host serves some 18 million sites. Mullenweg originally believed the March Distributed Denial of Service attack was motivated politically by China, though later he changed his thoughts on who the culprits may be. There’s no word yet that this April root break-in is politically motivated, but these attacks may be building to some sort of crescendo.

Jeff Hughes
Former Digital Trends Contributor
I'm a SF Bay Area-based writer/ninja that loves anything geek, tech, comic, social media or gaming-related.
Watch Boston Dynamics’ Atlas robot do a backflip in a Santa suit
watch boston dynamics atlas robot do a backflip in santa suit screenshot

Robotics specialist Boston Dynamics has posted a holiday message wishing everyone a “season full of light and laughter as we flip over into the new year!”

The flip reference becomes apparent when you watch the accompanying video featuring its Atlas robot performing a flawless back somersault -- dressed in a Santa suit.

Read more
I’m a Steam Deck apologist. Here’s why I’ve been using the ROG Ally instead
Elden Ring running on the Asus ROG Ally X.

Since its launch, I'm a bit of a Steam Deck apologist. It doesn't need the advocacy, as the Steam Deck is easily the best handheld gaming PC you can buy, but even in the face of competition from the ROG Ally, Lenovo Legion Go, and MSI Claw, I still use my Steam Deck for gaming on the go. A couple of apps have been slowly changing that story, however.

I like playing on my Steam Deck OLED due to the convenience. SteamOS isn't perfect, no, but it allows me to pick up and play my games quickly, which I value more than the higher performance available on Windows handhelds. A couple of key tweaks to the Windows experience can unlock that pick-up-and-play experience, and ever since configuring the ROG Ally X properly, I've been gravitating toward it more and more for my handheld gaming.
A proper sleep

Read more
Surfshark vs. Windscribe: Which unlimited device VPN is best?
Surfshark and Windscribe prices appear in a split-screen on a PC monitor.

You use more than one device, so it makes sense to use a VPN to protect privacy on all your computers, laptops, tablets, and phones. If you’re like me, that’s a lot of devices, making Surfshark and Windscribe top candidates.

While the best VPNs offer solid cybersecurity with excellent speed, some limit the number of simultaneous connections. That means you might need to disconnect your phone before using the VPN on your laptop. That can be frustrating if you've left your phone upstairs or in another room to charge, so I compared both Surfshark and Windscribe to see which is the better solution.
Specs

Read more