Skip to main content
Blog
Blog

Is Tuaw a scam in the making?

When we saw the new Fireship video, we were reminded of the recent Polyfill attack. Our first article was picked up by cybersecurity news outlets.

Aug 02, 2024 4 min read
Illustration for article about revived TUAW scam risk

TL;DR: expired domain revival scam risk

  • Expired domain, live inventory: An expired news domain is not a dead asset. It is inventory waiting for a buyer, and TUAW got picked up by a Hong Kong squatter called WebOrange that ran the old bylines through an AI rewriter and republished them under new names after legal pressure.
  • Polyfill went the same way: The Polyfill takeover took over 100,000 sites down the same path when its domain was acquired and used to inject malicious code. cside monitors every script and outbound link at runtime, including the ones your site still points at expired brands.
  • Audit old backlinks: Before you assume old backlinks are harmless, audit which of the domains they point to still exist under the original owner.

Short on time? See cside's in-browser Magecart and skimmer blocking. It covers everything below in one deployment.

When we saw the new Fireship video yesterday, we were immediately reminded of the recent Polyfill attack. Our first article was picked up and referenced by most cybersecurity news outlets, and a week later we published our full post-mortem.

When Fireship then reported on Tuaw, "The Unofficial Apple Weblog" a ton of people read back in the day, we thought it right to report on it as well.

A quick recap before we get into the troubling stuff:

Tuaw[.]com was acquired by AOL, but a few years later in 2015 it was shut down.

Though just a few weeks ago, the website was put back online. They ran most of the old articles through an AI rewriter and put them back online. First using old author names, then renaming a bunch as we'll see later on.

Also new articles have been added. A closer look reveals that these are likely also low-level AI generated and automated.

A Hong Kong based company named "WebOrange" squatted the domain and now owns this website.

The Fireship report ends there, but here's why we think this might be trouble in the making.

Be careful of Tuaw[.]com

In the recent Polyfill attack, we saw a case where a bunch of websites still referenced the domain Polyfill[.io] and others in their code. When the domain was then acquired, it was used to insert malicious code which redirected users to scammy websites.

Tuaw[.] immediately is less dangerous than Polyfill[.]io. As to our knowledge, they never spread scripts used by other websites. But since they once were a very popular news outlet, a lot of sites have links to their old articles.

One example we found is this on MacRumors forums:

MacRumors forum thread linking to an old TUAW article

That link "tuaw[.]com/2011/03/24/wooden-ipad-2-cover-outsmarts-apples-smart-cover/" redirects to "tuaw[.]com/ipad/accessories/".

Which could be suspicious, and is potentially a scam in the making.

LabelCantine dug a bit deeper a few weeks ago, and found that Tuaw changed the name of the old reporters after threatening legal action:

Screenshot showing TUAW renamed its old reporter bylines after legal pressure

We can also see the last uploaded articles we're all done so in minutes away from each other:

Recent TUAW article published just minutes apart from others

Third TUAW article in the batch published only minutes apart

Another TUAW article published just minutes apart from the others

And, while not foolproof, the image used for Paul Terpstra is likely AI-generated:

AI-Or-Not detector flagging a profile photo as likely AI-generated

The domain still holds a lot of SEO potential, and will easily start ranking high fast. Meaning all this could just be an SEO play meant to generate traffic. Monetization through ads or redirects are endings we've seen before.

The importance of client-side security

Pure client-side risks are low with Tuaw[.]com. Nevertheless, it's important to keep an eye on this domain. These other domains owned by this company according to LabelCantine linked above, followed similar techniques:

  • iLounge[.]com
  • Soup[.]io

If your site references any of them, we'd recommend you to review and remove them.

To keep your site safe from client-side JavaScript attacks, use cside for free now.

Simon Wijckmans
Founder & CEO

Founder and CEO of cside. Previously a product manager on Cloudflare Page Shield (now Cloudflare Client-Side Security). Co-chair of the W3C Anti-Fraud Community Group and a Forbes 30 Under 30 honoree. Building accessible security against client-side attacks, web security is not an enterprise-only problem.

FAQ

Frequently Asked Questions

The expired TUAW brand was bought and revived with AI-generated author photos and dozens of articles published minutes apart. The pattern matches a black-hat SEO play that recycles a once-trusted news brand for ad or affiliate revenue.

Treat any new TUAW article as low-trust until ownership is clarified. Former contributors should monitor whether their bylines were reused without consent and consider takedown requests.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead