Loading...
60+ essential cybersecurity terms explained in plain English. From APT to Zero-Day, master the language of information security.
A prolonged and targeted cyberattack where an attacker gains unauthorized access and remains undetected for an extended period to steal data.
A set of protocols that allows different software applications to communicate with each other.
A network of compromised computers controlled by an attacker to perform coordinated tasks like DDoS attacks.
An attack method that tries every possible combination of passwords until the correct one is found.
A vulnerability where a program writes data beyond the allocated memory buffer, potentially allowing code execution.
A standardized framework for rating the severity of security vulnerabilities on a scale of 0-10.
A publicly available list of known cybersecurity vulnerabilities, each with a unique identifier.
An attack that tricks an authenticated user into performing unintended actions on a web application.
The three pillars of information security: Confidentiality, Integrity, and Availability.
An attack that overwhelms a target server with traffic from multiple sources, making it unavailable.
The internet's phone book that translates domain names to IP addresses.
A part of the internet accessible only through special software like Tor, often associated with anonymous activities.
The process of converting plaintext data into ciphertext using an algorithm, making it unreadable without a decryption key.
A piece of code or technique that takes advantage of a vulnerability to compromise a system.
Security software that monitors endpoints for suspicious activity and responds to threats.
A network security device that monitors and filters incoming and outgoing traffic based on predefined rules.
An automated testing technique that provides random or unexpected data as input to find vulnerabilities.
European Union regulation for data protection and privacy.
Encryption programs used for secure communication and data integrity verification.
A decoy system designed to attract and detect attackers, providing early warning of attack attempts.
A fixed-length string generated from input data using a mathematical function, used to verify data integrity.
A web security policy mechanism that forces browsers to use HTTPS connections.
Systems that monitor network traffic for suspicious activity and can block potential threats.
A vulnerability where an application exposes internal object references, allowing unauthorized access.
A compact, URL-safe token format used for securely transmitting information between parties.
Malicious software that records keystrokes to capture sensitive information like passwords.
A network authentication protocol that uses tickets to verify user identity.
A vulnerability that allows an attacker to include local files on the server through the web application.
Techniques used by attackers to move through a network after gaining initial access.
Malicious software designed to harm, exploit, or compromise computer systems.
An attack where the attacker secretly intercepts and potentially alters communication between two parties.
A security method requiring two or more verification factors to access an account.
A network scanning tool used for host discovery, port scanning, and service detection.
The National Institute of Standards and Technology, which publishes cybersecurity frameworks and guidelines.
Intelligence gathered from publicly available sources for security research.
A nonprofit foundation producing widely referenced web security resources including the OWASP Top 10.
The part of malware or exploit that performs the intended malicious action.
A social engineering attack using fraudulent communications to trick victims into revealing sensitive information.
An authorized simulated attack on a system to evaluate its security.
Exploiting a vulnerability to gain elevated access rights beyond what was initially authorized.
Malware that encrypts victim's files and demands payment for decryption.
A vulnerability that allows an attacker to run arbitrary code on a target system remotely.
A connection where the target machine initiates a connection back to the attacker's machine, giving the attacker command-line access.
A group that simulates real-world attacks to test an organization's defenses.
An attack that inserts malicious SQL queries through application input to manipulate databases.
A vulnerability where an attacker can make a server perform requests to unintended locations.
A platform that collects, analyzes, and correlates security event data from multiple sources.
A centralized team that monitors and responds to cybersecurity incidents.
Cryptographic protocols that provide secure communication over computer networks.
A structured approach to identifying, quantifying, and addressing security threats to a system.
A subset of MFA requiring exactly two verification factors.
A service that creates an encrypted tunnel between your device and the internet.
A weakness in a system that can be exploited by a threat actor.
A security solution that filters and monitors HTTP traffic between a web application and the internet.
Self-replicating malware that spreads across networks without user interaction.
A vulnerability where an attacker injects malicious scripts into web pages viewed by other users.
An attack targeting applications that parse XML input, potentially exposing internal files.
A security model that requires strict verification for every person and device trying to access resources, regardless of location.
A vulnerability unknown to the software vendor, with no available patch at the time of discovery.