• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
  • Upcoming Events
    • TWS, Singapore (July 28-29, 2025)
    • WFIS, Philippines (September 23-24, 2025)
    • Fintech Revolution Summit, Vietnam (September 24, 2025)
    • Forex Expo Dubai (October 6-7, 2025)
    • Merge Madrid (October 7-9, 2025)
    • European Blockchain Convention, Barcelona (October 15-17, 2025)
    • Blockchain Futurist Conference, Florida (November 5-6, 2025)
    • Fintech Revolution Summit, Saudi Arabia (November 3, 2025)
    • WFIS, Indonesia (November 25-26, 2025)
  • Past Events
    • Blockchain Life
    • BlockShow Europe
    • Event Horizon

Crypto Reporter

Online magazine about cryptocurrencies, NFTs, DeFi, GameFi and other blockchain technologies

Join us on Telegram: https://t.me/crypto_reporter
  • News
    • News Feed
    • Cryptocurrencies
      • Bitcoin
      • Altcoins
    • Payment solutions
    • Exchanges
      • Binance
      • bitFlyer
      • Bitfinex
      • CBOE
      • CME
      • Coinbase
      • Coincheck
      • Coinfloor
      • Nasdaq
      • Poloniex
    • Regulations
      • Australia
      • Belarus
      • China
      • Europe
      • India
      • Iran
      • Israel
      • Japan
      • North Korea
      • Philippines
      • Portugal
      • Russia
      • South Korea
      • Thailand
      • Turkey
      • Venezuela
      • Vietnam
      • United States
    • Blockchain platforms
    • Crypto news in brief
    • Stats & trends
    • Reviews
      • Ambrosus
      • ATN
      • Dash
      • Green Power Exchange
      • Power Ledger
      • ShapeShift
      • Waltonchain
      • Cryptocurrency market capitalization can top 4 trillion USD, under conservative estimates
    • Opinion
    • Sponsored
  • Press Releases

New cside Report Shows Surge in Browser-Side Security Threats: Over 72,000 Websites Compromised in Q2 2025

July 30, 2025 By GlobeNewswire

  • Client-side attacks are rapidly evolving, ranging from OAuth abuse to crypto wallet drainers
  • WordPress and mobile browsers have been the primary targets
  • Compliance risks are mounting under GDPR, PCI DSS 4.0.1, and CCPA

SAN FRANCISCO, July 30, 2025 (GLOBE NEWSWIRE) -- cside, which specializes in securing vulnerable web dependencies, today released the Q2 2025 Client-Side Attack Report. The report reveals a sharp and concerning rise in web-based attacks targeting mobile browsers, content management systems, and vulnerable third-party JavaScript dependencies. The company’s Threat Research Team identified more than 72,000 compromised websites, including cryptocurrency platforms, e-commerce storefronts, and high-traffic media sites.

Unlike traditional server-based breaches, these attacks take place in the user’s browser. Attackers are embedding malicious scripts, hijacking OAuth flows, and deploying visually indistinguishable phishing pages to steal data and drain assets, all while bypassing backend security controls.

“These aren’t theoretical risks. They’re happening now, and they’re happening at scale,” said Himanshu Anand, a security analyst at cside who leads the Threat Research Team. “Attackers are exploiting the blind spots that traditional security tools miss: real-time browser behavior, mobile interactions, and the uncontrolled sprawl of third-party JavaScript. This quarter, we saw proof that even small gaps in client-side security can lead to major financial and compliance fallout.”

Among the key trends identified in the report:

  • Mobile-first attack campaigns that deploy malicious Progressive Web Apps (PWAs), often using adult content lures.
  • OAuth hijacking that abuses Google login flows to steal session tokens via WebSocket connections.
  • Wallet drainer injections and credential theft enabled by SEO poisoning and fake content delivery networks.
  • Cross-platform plugin exploitation through tools like ClickFix, enabling persistent payload injection across WordPress, Joomla, and custom CMSes.

The report identified 72,740 compromised websites, four brand-new attack techniques, and two major plugin-based supply chain breaches. The most affected industries included e-commerce, crypto, SMBs, and media. WordPress remains the top CMS target due to its global ubiquity and plugin fragmentation. The crypto sector, though smaller in volume, saw some of the most severe attacks, including real-world asset losses from wallet-draining campaigns. The incidents also carried regulatory implications under GDPR, PCI DSS 4.0.1, and CCPA.

To help organizations mitigate these risks, cside recommends a shift in browser-side security posture:

  • Treat all third-party scripts as untrusted by default
  • Deploy behavioral runtime detection to catch threats inside the live browser session
  • Harden CMS platforms, particularly WordPress, against plugin-based exploits
  • Develop targeted incident playbooks for Magecart-style attacks, plugin hijacking, and credential theft
  • Maintain active compliance alignment with evolving standards under GDPR, PCI-DSS 4.0.1, and CCPA

Looking ahead, the report anticipates an increase in AI-generated phishing campaigns, the broader use of wallet drainers on Solana and L2 chains, and continued abuse of browser-native APIs, such as OAuth and WebSocket.

Executives, CISOs, compliance professionals, and security teams can download the full Q2 2025 Client-Side Attack Report at: https://cside.dev/blog/client-side-attack-report-q2-2025

About cside

cside is a venture-backed cybersecurity company specializing in browser-side threat detection and protection. The company’s platform provides complete visibility and control over vulnerable first- and third-party scripts running on websites, protecting sensitive visitor data while ensuring optimal website performance. cside’s innovative technology enables customers to secure their web supply chain against sophisticated attacks and streamlines compliance with regulations such as PCI DSS 4.0.1.

Contact
Bret Clement
Clement | Peterson // bret@clementpeterson.com


Filed Under: News Feed

Primary Sidebar

Follow Us

Press Releases

Immunefi Adds Onchain Monitoring to Protect $180B+ in Digital assets as 2025 Crypto Hacks Top $3.1B

August 1, 2025

YGG Play Signs First Publishing Agreement with Gigaverse, Enables Transparent Onchain Revenue Share

August 1, 2025

xTAO Provides Update on TAO Holdings, Becomes Largest Publicly Traded Holder of TAO

August 1, 2025

Crypto Presale News: Can Ozak AI Follow Ethereum’s $4,000 Path?

August 1, 2025

Solana Eyes 66% Price Jump as Network Demand Grows, While Little Pepe’s (LILPEPE) Investor Base Grows Fast in 2025

August 1, 2025

TWS Conference

Forex Expo Dubai

Merge Madrid

Futurist Conference

Footer

Crypto Reporter is an online magazine about cryptocurrencies, NFTs, DeFi, GameFi and other blockchain technologies
About us
Contact us
Submit press-release

Search

2017-2025 Crypto Reporter