/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Nasty web bug descends on world's most popular sites

ING, New York Times bitten hard  —  Underscoring the severity of of an exotic form of website bug, security researchers from Princeton University have cataloged four cross-site request forgeries in some of the world's most popular sites.

The Register Dan Goodin

Context & Ripple Effects

Princeton researchers cataloging four cross-site request forgery (CSRF) flaws on marquee properties like ING and the New York Times extends a pattern of high-profile web properties being turned against their own visitors — following IndiaTimes being caught 'attacking visitors' in late 2007 and the compromise of the Department of Homeland Security's own website months earlier. The throughline is that even trusted, heavily trafficked domains can no longer be assumed safe surfaces for users.

First-order effects

  • ING and New York Times users are directly exposed: authenticated sessions on those sites can be hijacked by forged requests, meaning actions taken while logged in can be manipulated without the user's knowledge.
  • Both organizations face immediate remediation pressure — patching CSRF vectors on banking and news properties where trust is the core product.

Second-order effects

  • Other major sites running similar session-based architectures must audit for the same flaw class, since Princeton's cataloging suggests CSRF is widespread rather than isolated to these four instances.
  • Security vendors and browser makers gain a selling point for defenses (token validation, same-origin enforcement), shifting CSRF from an academic curiosity to a checklist item in enterprise web security.

Third-order effects

  • If trusted-brand websites remain attackable at scale, the implicit 'the URL in the address bar means safety' contract erodes, pushing the industry toward structural fixes baked into browsers and protocols rather than per-site patching.
  • Academic security research of this kind becomes a de facto audit layer for the web, with universities' disclosures increasingly driving what large commercial sites must fix.

The trend: The web's most trusted destinations are becoming its most valuable attack surfaces, forcing security from a per-site afterthought into platform- and protocol-level design.