Apparently the NBC site has been attacked and some malcious code has been placed on their web page.
More information can be found here:
There is a malicious iframe that is being used as the attack vector. The URLs that I found on the site (within the iframe) were categorized by trustedsource by the time I got to them.
I was however able to create a rule in MWG to remove iframes for sites in a given list, see screenshot below. Please keep in mind using the HTML opener can be a performance hit. This rule may need to be refined for production use and may produce false positives:
Just thought I'd share in case someone else read the news.
As of right now I think the code may have been taken down. The site I was testing with is no longer exibiting the behavior.
Thx, Jon, for the solution and for the update!
Not just nbc.com.
Also a bunch of *.msn.com sites and at least one *.foxsports.com site.