Over the past few days, companies web hosting have reported seeing attacks brute force being carried out on websites built with Joomla and WordPress.
Attackers are using a botnet with more than 90,000 servers to gain access to website administrator panels , trying to " guess" the username and password .
Security firm Sucuri reported that it has blocked 773,104 during the first 10 days of April.
Web hosting providers such as HostGator , InMotion and Melbourne Server Hosting advise their customers to change their administrator passwords to something more secure .
The issue is so serious that even WordPress founder Matt Mullenweg has written a blog post about the issue .
“ There is currently a botnet searching all websites that are set up with WordPresses , trying to log in with the 'admin' name and many different, common passwords .”
He advises users who are still using “ admin ” as their username to change it immediately and use a strong password .

