cd /news/cybersecurity/why-are-top-university-websites-serv… · home topics cybersecurity article
[ARTICLE · art-8648] src=arstechnica.com pub= topic=cybersecurity verified=true sentiment=↓ negative

Why are top university websites serving porn? It comes down to shoddy housekeeping.

A security researcher discovered that hundreds of subdomains belonging to at least 34 prestigious universities, including UC Berkeley, Columbia, and Washington University in St. Louis, are serving explicit pornographic content and malicious scam pages. The exploitation occurs because site administrators fail to delete old DNS records (CNAME records) after decommissioning subdomains, allowing scammers from a group known as Hazy Hawk to hijack the abandoned records. These hijacked pages then rank highly in Google search results due to the universities' strong reputations.

read1 min views6 publishedApr 24, 2026

Websites for some of the world’s most prestigious universities are serving explicit porn and malicious content after scammers exploited the shoddy record-keeping of the site administrators, a researcher found recently. The sites included berkeley.edu, columbia.edu, and washu.edu, the official domains for the University of California, Berkeley, Columbia University, and Washington University in St. Louis. Subdomains such as hXXps://causal.stat.berkeley.edu/ymy/video/xxx-porn-girl-and-boy-ej5210.html, hXXps://conversion-dev.svc.cul.columbia[.]edu/brazzers-gym-porn, and hXXps://provost.washu.edu/app/uploads/formidable/6/dmkcsex-10.pdf. All deliver explicit pornography and, in at least one case, a scam site falsely claiming a visitor’s computer is infected and advising the visitor to pay a fee for the non-existent malware to be removed. In all, researcher Alex Shakhov said, hundreds of subdomains for at least 34 universities are being abused. Search results returned by Google list thousands of hijacked pages. Hijacking a university’s good name Shakhov, founder of SH Consulting, said that the scammers—which a separate researcher has linked to a known group tracked as Hazy Hawk—are seizing on what amounts to a clerical error by site administrators of the affected universities. When they commission a subdomain such as provost.washu.edu, they create a CNAME record, which assignes a subdomain to a “canonical” domain. When the subdomain is eventually decommissioned—something that happens frequently for various reasons—the record is never removed. Scammers like Hazy Hawk then swoop in by hijacking the old record. With that, they have now hijacked that university’s subdomain. Given the reputations universities have, search queries then flow to the top of Google’s results.

── more in #cybersecurity 4 stories · sorted by recency
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/why-are-top-universi…] indexed:0 read:1min 2026-04-24 ·