Even though the post title and first paragraph are about calling out a sound-and-fury-signifying-nothing alert, most of his post is good stuff on WordPress, with lots of links.
… there is a wave of attacks going around targeting old WordPress blogs, particularly those on the 2.1 or 2.2 branch. They’re exploiting problems that have been fixed for a year or more. This typically manifests itself through hidden spam being put on your site, either in the post or in a directory, and people notice when they get dropped from Google.
Trackbacks & Pingbacks 2
[...] I don’t ever want to go back to the download-unzip-upload stuff I used to do. In a post I referenced earlier, Matt [...]
[...] I’ve already hit on SQL injection issues twice in the past two days (here directly and here indirectly through the non-issue with WP and SQL injection), why not add a cartoon to the [...]