Published event
ArtificialIntelligence Acquisition 3 source(s)

When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts

Updated September 26, 2026 · 2:44 PM · source date September 15, 2026

Summary

When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts A modern storefront can look perfectly healthy while malicious JavaScript works underneath: siphoning affiliate revenue, hijacking searches and clicks, tampering with analytics, or asking a remote server what to execute next. Pages load, products appear, and checkout works — yet the browser may be quietly doing something the site owner never authorized.

Why it matters

This Acquisition is relevant to the technology intelligence record because it involves Cloudflare, Amazon Web Services, Intel, Google. The source article should remain the factual reference for follow-up coverage.

Key facts
  • A modern storefront can look perfectly healthy while malicious JavaScript works underneath: siphoning affiliate revenue, hijacking searches and clicks, tampering with analytics, or asking a remote server what to execute next.
  • Pages load, products appear, and checkout works — yet the browser may be quietly doing something the site owner never authorized.
  • That is the blind spot our Client-Side Security machine learning (ML) model is built to expose.
  • This post follows four operations, spanning eight payloads, that our Page Shield ML uncovered in the wild.
  • The detection of these malicious payloads was automated; humans verified each finding only after the system had flagged it.
  • When we afterward reviewed the campaigns using security scanning tools, seven of the eight payloads were entirely absent from VirusTotal, and URLScan returned no malicious verdict for any of them.
Entities in this story
Related events