Michael Dinowitz just posted in the CF-talk list that the HoF site has been infected with some sort of malware script tag. He's in the process of fixing it now.
Working on it now. I'm concerned that only .cfm files were altered and only those on websites mapped through iis. I wonder if this is an iis based attack