csideai Profile Banner
cside Profile
cside

@csideai

Followers
267
Following
151
Media
83
Statuses
168

The only client-side cyber security company with a proxy solution. We monitor, analyze, speed up and autonomously block malicous 3rd party JavaScripts

Joined March 2024
Don't wanna be here? Send us removal request.
@csideai
cside
1 month
🚨 Magecart Alert 🚨.A live Magecart skimmer on payment pages is exfiltrating credit card data in violation of PCI DSS. Script downloaded from: hxxps://meriksshadowfiend[.]top/moritz-ca/metrics.js. Sending stolen data to:.hxxps://pixelnotinggo[.]top/api/accept-metrics
Tweet media one
0
1
5
@csideai
cside
1 month
Multiple shipped features this month 🤩.Full details on cside. dev/changelog.
0
0
4
@grok
Grok
6 days
What do you want to know?.
466
302
2K
@csideai
cside
1 month
A browser extension can quietly remove critical security headers like CSP. No warning. No consent. You install an extension and suddenly, protections against data leaks and injections are gone. Should we make this an explicit opt-in?. Or will that see no adoption?
Tweet media one
0
0
3
@csideai
cside
1 month
❗️We've identified a Magecart-like attack on the OpenCart CMS platform, mainly targeting East-Asian e-commerce websites.
0
1
1
@csideai
cside
2 months
This is what makes client-side attacks so dangerous. Dynamism is a sword that cuts both ways. Attacker leverage this to stay undetected for days, weeks and months.
0
0
2
@csideai
cside
2 months
Read our full report:.
0
0
0
@csideai
cside
2 months
Yesterday CoinMarketCap got struck by a substantial client-side attack. Impacting all logged in users to reauthenticate their wallet access, and inadvertently grating access to a bad actor.
1
0
1
@csideai
cside
3 months
Hello from Gartner!.Come visit us at booth 971 in the startup zone.
Tweet media one
0
0
0
@csideai
cside
3 months
We analyzed an attack on a Magento-based eCommerce site. The injection technique used hides in plain sight as the attacker is using ‘Google .com’ to deliver and execute their own code.
0
3
5
@csideai
cside
3 months
We’re at InfoSec all week!.Booth B133, come say hi!
Tweet media one
0
1
2
@csideai
cside
3 months
A new attack found in Progressive Web Apps (PWAs). They are browser-based too after all, and are also targets in client-side attacks.
0
2
4
@csideai
cside
3 months
If you’re serious about client-side security, you need runtime protection that sees what scripts actually do in your users' browsers. CSP is like locking your front door while leaving the windows wide open.
0
0
1
@csideai
cside
3 months
If you believe “strict CSP” is enough, look at Magecart, PII leaks, or the rise of fake browser updates. CSP couldn't save them, and neither will it save you.
Tweet media one
1
0
2
@csideai
cside
3 months
"But we use CSP so we're fine". ❌ No, you’re not. CSP was designed to protect you from things like XSS. But in reality, a CSP is blind as a bat. If you trust a vendor’s domain, CSP lets it right through. If that vendor gets compromised? CSP shrugs.
1
0
2
@csideai
cside
4 months
Thanks people at BSides and RSAC!.After the conferences, we hosted a rooftop afterparty for +500 people. A great way to close out the week. Thanks to @SocketSecurity, @arcjethq and @incident_io for co-hosting with us 💙
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
0
5
@csideai
cside
4 months
Here is how they tried it (and failed):.
0
1
2
@csideai
cside
4 months
Here is how they tried it (and failed):.
@csideai
cside
4 months
A few months ago we found North Korean operators trying to infiltrate our company. In collaboration with WIRED, we underwent thorough investigation and wrote our full story:.
0
0
1
@csideai
cside
4 months
A few months ago we found North Korean operators trying to infiltrate our company. In collaboration with WIRED, we underwent thorough investigation and wrote our full story:.
Tweet card summary image
wired.com
For years, North Korea has been secretly placing young IT workers inside Western companies. With AI, their schemes are now more devious—and effective—than ever.
1
3
8