No. This is serious business. I am not kidding. I was hacked! 

Okay, the better term is defaced. Not hack. Alright, not even defaced too much anyway. What he did (assuming that Rapcik0 is a man; not sure if this Turkish guy is a woman – I doubt that but hey, Trinity was being thought as a man. Okay stop thinking!) was changed my title post to HTML code that redirect to his site.
And the way he got to edit my title post is caused by the reset password vulnerability. Looks like he injected some SQL into the password reset function, and it give access to him. Then he changed the password of my Wordpress account.
Damn.
I thought this hole was fixed prior to Wordpress 2.8.6!
Okay fine. I went to cPanel, checked if he got that access, and apparently not. Reset all my password, and then changed the database. Got my access back, so I upgrade again to the latest Wordpress. Then I undo his change. At first I thought he put the redirection on the index.php, but apparently not. That’s when I realized it was at the post title.

Done!
P/s: Lesson learn – a good precaution is always use strong password, upgrade the security and apply the fixes, yada yada yada. Thank you for this reminder, Rapcik0.