Inside Coruna - Web Script IOS Exploit

Skip to main content
Recorded Webinar: Reducing Chargebacks with Browser-layer Intelligence (cside x Chargebacks911)

Latest Articles

Categories
Authors

Quick guide to prevent Account Takeover fraud (crypto websites)

Crypto accounts are the most valuable ATO target of any industry. See the best practices, fingerprint signals, and tools Crypto teams use to stop ATO.

Juan Combariza
Apr 17, 2026

How Advanced Location Data Prevents Account Takeover and Detects Unsafe AI-Agent Token Reuse

How advanced location data helps security teams detect impossible travel, stolen-session reuse, and unsafe AI-agent activity before account takeover turns into fraud or data loss.

Simon Wijckmans
Apr 15, 2026

How Compromised Third-Party Scripts Can Prompt-Inject AI Agents

Third-party scripts already adapt website behavior by browser characteristics. That same flexibility can be abused to detect AI agents and inject misleading instructions or altered content.

Simon Wijckmans
Apr 12, 2026

Best methods to prevent account takeover fraud (FinTech)

FinTech accounts are targeted daily by attackers. See the best practices, fingerprint signals, and prevention tools FinTech teams use to stop ATO.

Juan Combariza
Apr 9, 2026

Best practices to prevent account takeover fraud (eCommerce)

eCommerce accounts are targeted daily by attackers. See the best practices, fingerprint signals, and prevention tools eCom companies use to stop ATO.

Juan Combariza
Apr 8, 2026

How to Prevent Account Takeover Fraud | 4 Step Guide for Businesses

MFA helps, but it does not stop account takeover on its own. This guide covers how businesses can prevent ATO early with fingerprinting signals.

Juan Combariza
Apr 7, 2026

Meet cside at RSAC 2026

Meet the cside time at RSAC 2026 in San Francisco. Stop by our booth S-0238 on March 24-26 or grab time with us off the floor.

Juan Combariza
Mar 23, 2026

DarkSword: pure JavaScript exploit chain weaponizes legitimate websites

DarkSword is a full-chain iOS exploit delivered via watering-hole compromises of legitimate websites. It runs entirely in JavaScript, evades binary mitigations, and drops JavaScript-based backdoors that exfiltrate sensitive data.

Simon Wijckmans
Mar 20, 2026

OpenClaw Scanner for Third-Party Scripts

A free, open-source scanner that inventories third-party scripts, detects fingerprinting, audits security headers and cookies, and flags PCI DSS exposure on payment pages. Run a quick 30-second audit to reveal what code executes in your users' browsers.

Simon Wijckmans
Mar 18, 2026

AppsFlyer Web SDK supply-chain compromise - polymorphic crypto stealer

A registrar-level DNS hijack of appsflyer.com served a polymorphic crypto-stealing payload through the AppsFlyer Web SDK, affecting thousands of sites and some Node.js server environments. This post summarizes telemetry, forensic indicators, IOCs, detection guidance, and remediation steps.

Simon Wijckmans
Mar 18, 2026
Book a demo