.mobaxterm19436666DocsTechnology
Related
The Enduring Wisdom of The Mythical Man-Month: Lessons from Fred BrooksRevamping Search for Uninterrupted Availability: GitHub Enterprise Server's JourneyApple's iOS 27 Set to Transform iPhone Experience with AI-Powered Siri App and Satellite Upgrades, Sources SayEverything You Need to Know About the Ecovacs W3 Winbot Window Cleaning RobotApple Drops Safari Technology Preview 240 With Major CSS Revert-Rule Support and Critical Media Bug Fixes5 Essential Facts About Apple’s watchOS 26.5, tvOS 26.5, and visionOS 26.5 Release CandidatesMastering Cloud Testing: Strategies for Reliable Deployments10 Key Updates in Safari Technology Preview 242 You Should Know About

What You Need to Know About Why are top university websites serving porn? It ...

Last updated: 2026-04-30 18:44:26 · Technology

A handful of hijacked columbia.edu subdomains listed by Google One of the sites redirected by a UC Berkeley subdomain. Websites for some of the world’s most prestigious universities are serving explicit porn and malicious content after scammers exploited the shoddy record-keeping of the site administrators, a researcher found recently. The sites included berkeley.edu, columbia.edu, and washu.edu, the official domains for the University of California, Berkeley, Columbia University, and Washington University in St. Louis. Subdomains such as hXXps://causal.stat.berkeley.edu/ymy/video/xxx-porn-girl-and-boy-ej5210.html, hXXps://conversion-dev.svc.cul.columbia[.]edu/brazzers-gym-porn, and hXXps://provost.washu.edu/app/uploads/formidable/6/dmkcsex-10.pdf. All deliver explicit pornography and, in at least one case, a scam site falsely claiming a visitor’s computer is infected and advising the visitor to pay a fee for the non-existent malware to be removed. In all, researcher Alex Shakhov said, hundreds of subdomains for at least 34 universities are being abused. Search results returned by Google list thousands of hijacked pages.

Hijacking a university's good name

Scammers like Hazy Hawk then swoop in by hijacking the old record.Read full article Comments Shakhov, founder of SH Consulting, said that the scammers—which a separate researcher has linked to a known group tracked as Hazy Hawk—are seizing on what amounts to a clerical error by site administrators of the affected universities. When they commission a subdomain such as provost.washu.edu, they create a CNAME record, which assignes a subdomain to a "canonical" domain. When the subdomain is eventually decommissioned—something that happens frequently for various reasons—the record is never removed.

you top university
Image via Flickr
What You Need to Know About Why are top university websites serving porn? It ...
Source: feeds.arstechnica.com