I just upgraded to WordPress 2.6.2. Apparently, there was a problem in 2.6.1 that allowed a user to reset the password for any user, and I’m pretty sure I was hit with it right before I upgraded. I got an email saying that a new user had registered and then reset their password, using the username ‘admin’. Fortunately, I’ve modified my site to use an alternate username for the administrative user, so I wasn’t affected by this.