Usa.Kaspersky.com hacked
hackersblog.org
hackersblog.org
One more reason to make sure you check each and every avenue of user supplied data for SQL injection. What really surprises me is that they don't use prepared statements.
Probably for the "fame". I have to say I'm hardly impressed by the recent exploits that I've seen, the phpBB.com one for example.