Top Universities' Websites Compromised by Scammers Serving Explicit Content
Why are top university websites serving porn? It comes down to shoddy housekeeping.
Ars Technica
Image: Ars Technica
Websites of prestigious universities, including the University of California, Berkeley, Columbia University, and Washington University in St. Louis, are being exploited by scammers to serve explicit pornography and malicious content. This issue arises from poor record-keeping by site administrators, allowing attackers to hijack expired subdomains.
- 01Scammers are exploiting poor record-keeping by university site administrators.
- 02At least 34 universities have been affected, with hundreds of subdomains compromised.
- 03The group behind the attacks is linked to a known entity called Hazy Hawk.
- 04Hijacked subdomains deliver explicit content and potential scams.
- 05Search engines are returning thousands of hijacked pages in search results.
Advertisement
In-Article Ad
Recent findings reveal that websites of several top universities, including the University of California, Berkeley, Columbia University, and Washington University in St. Louis, are serving explicit pornography and malicious content due to exploitation by scammers. Researcher Alex Shakhov from SH Consulting identified that hundreds of subdomains from at least 34 universities have been compromised. The attackers, linked to a group known as Hazy Hawk, take advantage of poor record-keeping practices by university administrators. When a subdomain is decommissioned, the corresponding CNAME record is often left intact, allowing scammers to register the expired domain and redirect it to explicit content or scam sites. This issue has resulted in thousands of hijacked pages appearing in search engine results, raising concerns about the reputation and security of these prestigious institutions.
Advertisement
In-Article Ad
This situation could damage the reputations of affected universities and expose users to malicious content.
Advertisement
In-Article Ad
Reader Poll
Should universities invest more in cybersecurity measures?
Connecting to poll...
Read the original article
Visit the source for the complete story.


