:

UNIVERSITY WEBSITES HIJACKED TO SERVE PORNOGRAPHY

INDUSTRY DESK1 MIN READ
FRI, APR 24, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Hundreds of subdomains across dozens of top universities have been compromised by scammers and are now hosting adult content. The breach stems from poor website maintenance and security practices.

Researchers discovered that inactive university subdomains—many tied to defunct projects, old departments, or abandoned initiatives—lack proper oversight and security controls. Scammers exploit this negligence by gaining access and redirecting traffic to pornographic sites, damaging institutional reputation. The hijacked domains retain authority from their parent university websites, allowing them to rank highly in search results and appear legitimate to users. This makes them valuable real estate for malicious actors seeking to monetize adult content through advertising. The issue reflects broader challenges in digital housekeeping at large institutions. Universities often maintain thousands of subdomains across departments, research groups, and legacy systems. Without centralized inventory and monitoring, inactive domains become security blind spots. Expert recommendations include conducting subdomain audits, removing unused domains, implementing security headers, and establishing continuous monitoring. Universities are being urged to treat dormant web properties as potential vulnerabilities rather than harmless digital debris.

■ SOURCES

Ars Technica

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Illinois county prosecutors secretly provided personal information about criminal defendants to federal immigration agents without warrants, public disclosure, or legislative approval.

1H AGOIndustry Desk

Law enforcement from 22 countries arrested 58 individuals and identified 263 suspects in a coordinated crackdown on cybercrime networks run by African crime groups.

1H AGOSecurity Desk

The Los Angeles County Museum of Art disclosed a data breach from last year that compromised customer and employee information, including social security numbers and medical records.

4H AGOSecurity Desk

A phishing-as-a-service platform called AnonyMousKIT uses voice AI agents to extract passcodes from stolen Apple devices and bypass Activation Lock security features.

6H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.