Security Alert: Upgrade WordPress Today To 2.8.4

Another reason for always installing the latest updates, is to make sure your software is always safe.  There is a worm that is attacking old WordPress installations.  If you are not running WordPress 2.8.4 then please upgrade now.:

This particular worm, like many before it, is clever: it registers a user, uses a security bug (fixed earlier in the year) to allow evaluated code to be executed through the permalink structure, makes itself an admin, then uses JavaScript to hide itself when you look at users page, attempts to clean up after itself, then goes quiet so you never notice while it inserts hidden spam and malware into your old posts.

The tactics are new, but the strategy is not. Where this particular worm messes up is in the “clean up” phase: it doesn’t hide itself well and the blogger notices that all his links are broken, which causes him to dig deeper and notice the extent of the damage.

Attacks against WordPress are getting more frequent now because hackers have a sizeble base to go after now, so please always install WP updates as they come out.