Right now there?s a botnet going around all of the WordPresses it can find trying to login with the ?admin? username and a bunch of common passwords[...]
Here?s what I would recommend: If you still use ?admin? as a username on your blog, change it, use a strong password, if you?re on WP.com turn on two-factor authentication, and of course make sure you?re up-to-date on the latest version of WordPress.
via Matt Mullenweg