just posted in their official sites : source : http://www.simplemachines.org/community/index.php?topic=508232.new#new
Security breaches are not uncommon with SMF and it is generally frowned upon to report them. Most people will avoid reporting this problem because they are met with denial IE there are no security issues. There is supposed to be a new version 2.1 that is said to fix many of the issues ignored in 2.0.4 and previous versions but one just has to look at the reluctance to fix current bugs and security issues to see this 2.1 update will in all likely hood be a new version of previous screw ups.
based on their announcement , this breach is not because of flaw in SMF script, but because weak password used by one of their admin. like ubuntu case and other recent breach
LOL the flaws are never in SMF according to their support people. It's either the user, or more often they say it is the host.
I've just read through many of the posts about this security issue on their forum and others and it would seem that person is being thrown under the bus.
I seen this on Simplemachines it self its pretty bad i always trusted SMF in like covering my details but seems not, MyBB is better nevertheless.