Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

April WordPress hack the latest in long line of similar attacks

Add as a preferred source on Google

WordPress LogoAutomattic, the purveyor of WordPress, has suffered a recent security breach that could present to significant security risk for WordPress-powered sites.

“Automattic had a low-level (root) break-in to several of our servers, and potentially anything on those servers could have been revealed,” WordPress founder Matt Mullenweg explained on the WordPress blog, on Wednesday. Mullenweg goes on to write that WordPress is reviewing the logs and suspects its source code was copied. The company has little advice for users, other than to strengthen their passwords. Not only is the WordPress blog hosting affected, but many of Automattic’s other services are potentially at-risk.

Recommended Videos

The consequences of this attack by hackers will definitely be felt by the major VIP members of the WordPress service such as NASA, CBS and The New York Times. Alexia Tsosis from TechCrunch (also a VIP member) says “VIP customers are all on ‘code red’ and in the process of changing all the passwords/API keys they’ve left in the source code.”  Tsosis says that Automattic is downplaying the potential severity of this attack.

There have been a bevy of hack attacks occurring lately against big name companies, such as the DDoS attacks against Sony PlayStation by Anonymous, as well as the EMC breach, Epsilon, and lets not forget that this isn’t the first time WordPress has been attacked.

WordPress was hit hard in 2009 when hidden admin accounts were creating back doors. Just last month, WordPress also suffered a huge DDoS attack, affecting 10 percent of its hosted sites. Let’s remember that this blog host serves some 18 million sites. Mullenweg originally believed the March Distributed Denial of Service attack was motivated politically by China, though later he changed his thoughts on who the culprits may be. There’s no word yet that this April root break-in is politically motivated, but these attacks may be building to some sort of crescendo.

Jeff Hughes
Former Digital Trends Contributor
I'm a SF Bay Area-based writer/ninja that loves anything geek, tech, comic, social media or gaming-related.
Apple Creator Studio adds AI tools across Final Cut Pro, Logic Pro and Pixelmator Pro
Final Cut Pro gets AI captions, Auto Mask and better Pixelmator Pro workflows in Creator Studio update
Computer Hardware, Electronics, Hardware

Apple has introduced a major update to Apple Creator Studio, adding new AI features, deeper Pixelmator Pro integration, and workflow upgrades across Final Cut Pro, Logic Pro, Keynote, Pages, Numbers, Motion, Compressor, Freeform, and Final Cut Camera.

The update makes Creator Studio more useful across Mac, iPad, and iPhone, especially for people who move between video editing, image editing, presentations, documents, spreadsheets, and music production.

Read more
AI browsers like Perplexity Comet can be tricked into spilling your password through BioShocking exploit
Six AI browsers were found leaking saved passwords and many of them haven't fixed it yet.
MacBook Air in hand, Comet browser loaded—let’s see what Perplexity’s AI can really do

Security researchers just found a strange way to trick AI browsers into handing over your passwords. They managed to trick AI browser agents into exposing sensitive data like saved passwords, session cookies, and private tokens by disguising the theft as part of a harmless "game."

The technique is called BioShocking, named after the popular video game BioShock, where a brainwashed character is manipulated into believing a false reality. Once an AI browser falls for the same trick, it stops following its own safety rules entirely.

Read more
Google Play’s latest speed boost goes way beyond the phone
Play Store v52.1 targets app install performance across Android devices, including cars, TVs, watches, tablets, and phones.
Google Play Store Photo

Google is rolling out Play Store v52.1 with changes built around a practical Android problem, getting apps installed more smoothly on very different kinds of hardware.

The update focuses on Play Store infrastructure, with Google pointing to stability, performance, and better memory use while a device adds an app. That install path now has to work on phones, tablets, Wear OS watches, Google TV, Android TV, Android Auto, and cars running Android Automotive.

Read more