Those brute force attacks are just the most recent and high profile.
wordpress is just full of little holes... like this
http://packetstormsecurity.com/files...spider-sql.txt
There are so many of these type of security 'holes' in wordpress that I could spend all day just gathering links to articles like that one.
I know a lot of folks like and use WP. But I sure would not use it, at least for a site I wanted to make money with.
But then again that is just me.
The wp plug in better security does use a different url to login... but it childs play to figure out what it is.