When Scanners Miss the Attack: How Cloudflare Client-Side Security Protects Storefronts
Cloudflare, Wednesday, September 16th, 2026
Cloudflare Client-Side Security uncovered four malicious campaigns that conventional scanners failed to detect on e-commerce sites.
Cloudflare reports on four malicious client-side campaigns found by its Client-Side Security product on customer storefronts.
The post explains why server-side scanning misses these attacks: the malicious behavior only executes in the visitor's browser, often conditionally and only on checkout pages.
It walks through the specific skimming and injection techniques used and how script monitoring detected the anomalous behavior.
Cloudflare covers the implications for PCI DSS requirements around payment page script integrity.