{"id":324995,"date":"2026-04-26T21:43:20","date_gmt":"2026-04-26T16:13:20","guid":{"rendered":"https:\/\/ebiztoday.news\/?p=324995"},"modified":"2026-04-26T21:43:20","modified_gmt":"2026-04-26T16:13:20","slug":"why-are-top-university-web-sites-serving-porn-it-comes-right-down-to-shoddy-housekeeping","status":"publish","type":"post","link":"https:\/\/ebiztoday.news\/index.php\/2026\/04\/26\/why-are-top-university-web-sites-serving-porn-it-comes-right-down-to-shoddy-housekeeping\/","title":{"rendered":"Why are top university web sites serving porn? It comes right down to shoddy housekeeping."},"content":{"rendered":"<p><\/p>\n<div>\n<p>Web sites for a number of the world\u2019s most prestigious universities are serving explicit porn and malicious content after scammers exploited the shoddy record-keeping of the location administrators, a researcher found recently.<\/p>\n<p>The sites included berkeley.edu, columbia.edu, and washu.edu, the official domains for the University of California, Berkeley, Columbia University, and Washington University in St. Louis. Subdomains akin to hXXps:\/\/causal.stat.berkeley.edu\/ymy\/video\/xxx-porn-girl-and-boy-ej5210.html, hXXps:\/\/conversion-dev.svc.cul.columbia[.]edu\/brazzers-gym-porn, and hXXps:\/\/provost.washu.edu\/app\/uploads\/formidable\/6\/dmkcsex-10.pdf. All deliver explicit pornography and, in a minimum of one case, a scam site falsely claiming a visitor\u2019s computer is infected and advising the visitor to pay a fee for the non-existent malware to be removed. In all, researcher Alex Shakhov said, tons of of subdomains for a minimum of 34 universities are being abused. Search results returned by Google list hundreds of hijacked pages.<\/p>\n<figure class=\"ars-wp-img-shortcode id-2151496 align-none\">\n<div>\n<div class=\"ars-lightbox\">\n<div class=\"ars-lightbox-item\">\n            <a class=\"cursor-zoom-in\" data-pswp-width=\"2252\" data-pswp-height=\"1198\" data-pswp-srcset=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/hijacked-columbia-university-subdomains.png 2252w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/hijacked-columbia-university-subdomains-640x340.png 640w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/hijacked-columbia-university-subdomains-1024x545.png 1024w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/hijacked-columbia-university-subdomains-768x409.png 768w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/hijacked-columbia-university-subdomains-1536x817.png 1536w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/hijacked-columbia-university-subdomains-2048x1089.png 2048w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/hijacked-columbia-university-subdomains-980x521.png 980w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/hijacked-columbia-university-subdomains-1440x766.png 1440w\" data-cropped=\"false\" href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/hijacked-columbia-university-subdomains.png\" target=\"_blank\"><\/p>\n<p>            <\/a><\/p>\n<p>\n              A handful of hijacked columbia.edu subdomains listed by Google\n                          <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div><figcaption>\n<div class=\"caption font-impact dusk:text-gray-300 mb-4 mt-2 inline-flex flex-row items-stretch gap-1 text-base leading-tight text-gray-400 dark:text-gray-300\">\n<p>\n      A handful of hijacked columbia.edu subdomains listed by Google<\/p>\n<\/p><\/div>\n<\/figcaption><\/figure>\n<figure class=\"ars-wp-img-shortcode id-2151497 align-none\">\n<div>\n<div class=\"ars-lightbox\">\n<div class=\"ars-lightbox-item\">\n            <a class=\"cursor-zoom-in\" data-pswp-width=\"2550\" data-pswp-height=\"1552\" data-pswp-srcset=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain.png 2550w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-640x390.png 640w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-1024x623.png 1024w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-768x467.png 768w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-1536x935.png 1536w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-2048x1246.png 2048w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-980x596.png 980w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-1440x876.png 1440w\" data-cropped=\"false\" href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain.png\" target=\"_blank\"><br \/>\n              <img width=\"640\" height=\"390\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-640x390.png\" class=\"none medium\" alt=\"\" decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-640x390.png 640w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-1024x623.png 1024w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-768x467.png 768w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-1536x935.png 1536w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-2048x1246.png 2048w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-980x596.png 980w, https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2026\/04\/redicted-ucberkeley-subdomain-1440x876.png 1440w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\"\/><br \/>\n            <\/a><\/p>\n<p>\n              One in every of the sites redirected by a UC Berkeley subdomain.\n                          <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div><figcaption>\n<div class=\"caption font-impact dusk:text-gray-300 mb-4 mt-2 inline-flex flex-row items-stretch gap-1 text-base leading-tight text-gray-400 dark:text-gray-300\">\n<p>\n      One in every of the sites redirected by a UC Berkeley subdomain.<\/p>\n<\/p><\/div>\n<\/figcaption><\/figure>\n<h2>Hijacking a university\u2019s good name<\/h2>\n<p>Shakhov, founding father of SH Consulting, said that the scammers\u2014which a separate researcher has linked to a known group tracked as <a href=\"https:\/\/www.infoblox.com\/threat-intel\/threat-actors\/hazy-hawk\/\">Hazy Hawk<\/a>\u2014are seizing on what amounts to a clerical error by site administrators of the affected universities. After they commission a subdomain akin to provost.washu.edu, they create a <a href=\"https:\/\/en.wikipedia.org\/wiki\/CNAME_record\">CNAME<\/a> record, which assignes a subdomain to a \u201ccanonical\u201d domain. When the subdomain is eventually decommissioned\u2014something that happens steadily for various reasons\u2014the record is rarely removed. Scammers like Hazy Hawk then swoop in by hijacking the old record.<\/p>\n<p>With that, they&#8217;ve now hijacked that university\u2019s subdomain. Given the reputations universities have, search queries then flow to the highest of Google\u2019s results.<\/p>\n<\/p><\/div>\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Web sites for a number of the world\u2019s most prestigious universities are serving explicit porn and malicious content after scammers exploited the shoddy record-keeping of the location administrators, a researcher found recently. The sites included berkeley.edu, columbia.edu, and washu.edu, the official domains for the University of California, Berkeley, Columbia University, and Washington University in St. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":324996,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[51058,11806,4391,51057,1111,4752,1323],"class_list":["post-324995","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-housekeeping","tag-porn","tag-serving","tag-shoddy","tag-top","tag-university","tag-websites"],"aioseo_notices":[{"message":"The permalink for this post just changed! This could result in 404 errors for your site visitors.","status":"warning","options":{"id":"0a2ae5f84bc2c0423042ed7ec22d2e40","isDismissible":true,"actions":[{"url":"https:\/\/ebiztoday.news\/wp-admin\/admin.php?page=aioseo-redirects","label":"Add Redirect to improve SEO","class":"aioseo-redirects-slug-changed"}]},"allowedContexts":["posts"]}],"_links":{"self":[{"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/posts\/324995","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/comments?post=324995"}],"version-history":[{"count":2,"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/posts\/324995\/revisions"}],"predecessor-version":[{"id":324998,"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/posts\/324995\/revisions\/324998"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/media\/324996"}],"wp:attachment":[{"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/media?parent=324995"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/categories?post=324995"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ebiztoday.news\/index.php\/wp-json\/wp\/v2\/tags?post=324995"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}