Run any website and your logs will eventually be full of hits to /wp-admin /cgi-bin etc. from zombies scanning the net for known vulnerabilities. This has been going on forever.
And buzfeed could see this happening to them if they looked at their logfiles
Yep - this is why I ultimately gave up on hosting Wordpress at all and just went with Pantheon. The managed service to deal with this was easily worth more than constantly being paranoid as to whether I was up to date with the most recent types of Wordpress vulnerabilities.
This is less of a problem now, as wordpress now auto-updates by default.
This has been a hit and miss for me, and that's actually worse, because when I get that "wordpress has updated on its own" email I get the feeling of security, and then months later I log into the admin area only to find wordpress decided not to install a core update for... whatever reason