News Grower

Independent coverage of AI, startups, and technology.

Ars Technica Apr 24, 2026 at 19:00 Big Tech Stable Warm

Why are top university websites serving porn? It comes down to shoddy housekeeping.

Hundreds of subdomains from dozens of universities have been hijacked by scammers.

Signal weather

Stable

The story has moved beyond the first headline and now acts as a reliable context anchor.

By Dan Goodin Original source
Why are top university websites serving porn? It comes down to shoddy housekeeping.

Websites for some of the world’s most prestigious universities are serving explicit porn and malicious content after scammers exploited the shoddy record-keeping of the site administrators, a researcher found recently. The sites included berkeley.edu, columbia.edu, and washu.edu, the official domains for the University of California, Berkeley, Columbia University, and Washington University in St. Louis. Subdomains such as hXXps://causal.stat.berkeley.edu/ymy/video/xxx-porn-girl-and-boy-ej5210.html, hXXps://conversion-dev.svc.cul.columbia[.]edu/brazzers-gym-porn, and hXXps://provost.washu.edu/app/uploads/formidable/6/dmkcsex-10.pdf. All deliver explicit pornography and, in at least one case, a scam site falsely claiming a visitor’s computer is infected and advising the visitor to pay a fee for the non-existent malware to be removed. In all, researcher Alex Shakhov said, hundreds of subdomains for at least 34 universities are being abused. Search results returned by Google list thousands of hijacked pages. A handful of hijacked columbia.edu subdomains listed by Google One of the sites redirected by a UC Berkeley subdomain. Hijacking a university's good name Shakhov, founder of SH Consulting, said that the scammers—which a separate researcher has linked to a known group tracked as Hazy Hawk—are seizing on what amounts to a clerical error by site administrators of the affected universities. When they commission a subdomain such as provost.washu.edu, they create a CNAME record, which assignes a subdomain to a "canonical" domain. When the subdomain is eventually decommissioned—something that happens frequently for various reasons—the record is never removed. Scammers like Hazy Hawk then swoop in by hijacking the old record. Read full article Comments

Stay on the signal

Follow Why are top university websites serving porn? It comes down to shoddy housekeeping.

Follow this story beyond a single article: new follow-ups, adjacent sources, and the evolving storyline.

We send a confirmation link first, then only meaningful digests.

Story map

Understand this topic fast

A quick entry into the story: why it matters now, who is involved, and where to go next for context.

Why it matters now

This story is still moving and pulling follow-up coverage.
There are already 6 connected articles in the same storyline to continue from here.
The story keeps orbiting around Ars Technica, Housekeeping, and Hundreds, so the entity pages are the fastest way to build context.
Ars Technica already has 4 follow-up stories on the same theme.

Topic constellation

Open the live map for this story

See which entities, story threads, sources, and follow-up articles shape this story right now.

Click nodes to continue

Entity Cluster Article Hub Source

Story timeline

Continue with this story

A short sequence of events and follow-up stories to understand the arc quickly.

Jun 16, 2026 at 21:54 Ars Technica

Cockroaches scurry around with thousands of pieces of bacterial genomes

Transferring genes across species doesn't just happen in microbes.

Jun 16, 2026 at 21:14 Ars Technica

Among the large new rockets Amazon was counting on, only Europe has delivered

"As for Arianespace, they have definitely stepped up."

Jun 16, 2026 at 21:00 Ars Technica

Anthropic "pauses" token-based billing for its Claude Agent SDK

Move originally planned for Monday would have heavily increased power users' costs.

Jun 16, 2026 at 18:48 Ars Technica

US approval of Paramount/Warner Bros. deal surprised DOJ lawyers, report says

Trump admin green-lighting $111B deal "reeks of corruption," Sen. Warren says.

Jun 16, 2026 at 18:11 Ars Technica

Pentagon boasts of using AI to write reports mandated by Congress

Pentagon also claims 1.5 million personnel are using generative AI tools.

Apr 24, 2026 at 19:00 Ars Technica

Why are top university websites serving porn? It comes down to shoddy housekeeping.

Hundreds of subdomains from dozens of universities have been hijacked by scammers.

How reliable this looks

Signal and trust for Ars Technica

This source works at a rapid pace: 100% of recent stories land in the hot window, and 0% carry visible search signal.

Trusted

Reliability

92

Freshness

100

Sources in storyline

1

Related articles

More stories that share tags, source, or category context.

More from Ars Technica

Fresh reporting and follow-up coverage from the same newsroom.

Open source page