/>
X

WordPress firm Automattic suffers root-level hack

Hackers gained administrative privileges to a number of Automattic servers, WordPress founder Matt Mullenweg has said
tom-espiner.jpg
Written by Tom Espiner, Senior Reporter on

Automattic, the company behind blogging platform WordPress.com, has suffered an attack that gave hackers complete access to a number of its servers.

WordPress users should take precautions about their passwords, the site's founder Matt Mullenweg said in a blog post on Wednesday. WordPress has nearly 18 million hosted blogs.

"Automattic had a low-level (root) break-in to several of our servers, and potentially anything on those servers could have been revealed," Mullenweg said, adding that Automattic's source code, which is mainly open source, may have been exposed and copied.

The company uses cryptographic techniques including hashing and salting to make it difficult for hackers to crack WordPress users' password details, Mullenweg said. Nevertheless, people should use strong passwords and make sure not to reuse passwords across different websites, the WordPress founder noted.

The company is investigating the breach and has taken steps to re-secure "avenues used to gain access", he said.

WordPress has been the target of attacks in the past. In March the blogging platform underwent a large-scale denial-of-service attack that affected a number of blogs.


Get the latest technology news and analysis, blogs and reviews delivered directly to your inbox with ZDNet UK's newsletters.

Related

On July 12, we'll see the universe like never before
51656393132-ca88bc21e3-k

On July 12, we'll see the universe like never before

Space
My Bitcoin 'investment': After exactly six months, how much did I gain or lose?
crypto-on-paypal-2022-07-01-00-06-57

My Bitcoin 'investment': After exactly six months, how much did I gain or lose?

Bitcoin
Delta Air Lines just made an embarrassing announcement (you may be livid)
screen-shot-2022-06-22-at-3-50-54-pm.png

Delta Air Lines just made an embarrassing announcement (you may be livid)

Business