cside: Browser and device-side skeptical security to eliminate agent traction

An Intellyx Brain Candy Update

cside logo Intellyxcside intercepts malicious bot behavior and misdirects suspicious requests post-firewall, at the browser or device level, in order to invert the economies of scale of novel agentic attacks against themselves.

Since our last coverage of cside at RSAC 2025, the last mile of threat surface they cover has expanded exponentially thanks to AI-driven automation that any bad actor can use. Yes there are still fraudulent users, bot crawlers, porous browser extensions and ad fraud schemes, but exploits that live between the user session, the browser, and the device are now being deluged by tireless agentic attacks.

A lot of these agents are insider threats authorized by end users themselves. An employee may, for instance, grab an openclaw-style agent to act as a co-worker. By following a few install prompts, that agent gets local file access, installs its own browser extensions, and user credentials so it can log into any site. Maybe that agent follows instructions to gmail 100 more friends, or log into a bank …

Aside from cleaning up client-side vulnerabilities, on the preventative side the trick here is binding each user session to the browser and the device with a virtual “fingerprint” so the credentials aren’t portable. There’s also a cool feature that puts detected bots or agents into a harmless “hall of mirrors” which wastes their time and tokens, making the attacks themselves unsustainable.

Intellyx hot take: An infestation of agents gives cside a marketing assist right now, since WAFs don’t prevent client-side script execution, and the usual XDR and SIEM threat hunting patterns aren’t good at spotting client-side problems.

Intellyx cold take: Some less-than-honorable security vendors and consultants might actually depend upon the client-side loopholes cside would block. You know: they sell you a solution that solves the vuln they participated in creating by poking around your site, so they can ‘solve’ that for you. I will leave that there.

 

Copyright ©2026 Intellyx B.V. Intellyx is the change agent analyst firm focused on customer-driven, technology-empowered enterprise transformation. Our thought leadership distills insights across the rapidly evolving enterprise IT landscape, and our advisory helps you and your customers see through the hype and get beyond the fear of technology disruption to take action and realize value through change. At the time of writing, cside is not an Intellyx customer. No AI was used to write this article. To be considered for a Brain Candy article, email us at pr@intellyx.com.

SHARE THIS:

Principal Analyst & CMO, Intellyx. Twitter: @bluefug