Nasty web bug descends on world's most popular sites
ING, New York Times bitten hard — Underscoring the severity of of an exotic form of website bug, security researchers from Princeton University have cataloged four cross-site request forgeries in some of the world's most popular sites.
Context & Ripple Effects
Princeton researchers cataloging four cross-site request forgery (CSRF) flaws on marquee properties like ING and the New York Times extends a pattern of high-profile web properties being turned against their own visitors — following IndiaTimes being caught 'attacking visitors' in late 2007 and the compromise of the Department of Homeland Security's own website months earlier. The throughline is that even trusted, heavily trafficked domains can no longer be assumed safe surfaces for users.
First-order effects
- ING and New York Times users are directly exposed: authenticated sessions on those sites can be hijacked by forged requests, meaning actions taken while logged in can be manipulated without the user's knowledge.
- Both organizations face immediate remediation pressure — patching CSRF vectors on banking and news properties where trust is the core product.
Second-order effects
- Other major sites running similar session-based architectures must audit for the same flaw class, since Princeton's cataloging suggests CSRF is widespread rather than isolated to these four instances.
- Security vendors and browser makers gain a selling point for defenses (token validation, same-origin enforcement), shifting CSRF from an academic curiosity to a checklist item in enterprise web security.
Third-order effects
- If trusted-brand websites remain attackable at scale, the implicit 'the URL in the address bar means safety' contract erodes, pushing the industry toward structural fixes baked into browsers and protocols rather than per-site patching.
- Academic security research of this kind becomes a de facto audit layer for the web, with universities' disclosures increasingly driving what large commercial sites must fix.
The trend: The web's most trusted destinations are becoming its most valuable attack surfaces, forcing security from a per-site afterthought into platform- and protocol-level design.