Field glossary
Cybersecurity terms, in plain language
321 terms explained simply, in Azerbaijani and English — each on its own page.
#1
A19
- A800RTOTOLINK A800R is a specific wireless router model manufactured by TOTOLINK. It appears in threat intelligence reports as a device with identified vulnerabilities.
- ACLAn ACL (Access Control List) is a list of permissions that defines who can access a resource and at what level. In simple terms, it is a set of rules that tells the system 'who can open which door'.
- ACLsAn ACL (Access Control List) is a set of rules that defines allowed or denied traffic to network resources, typically applied on a router or firewall.
- ADActive Directory (AD) – A directory service developed by Microsoft for centralized management and authentication of network resources, users, and computers. It is a primary target for attackers aiming to escalate privileges and move laterally within a network.
- ADMADM (Active Directory Management) is a tool or platform used for administering Microsoft's Active Directory services, often enabling centralized management of group policies, user accounts, and security configurations.
- AESAES (Advanced Encryption Standard) is a symmetric block cipher algorithm used to secure data, employing the same key for both encryption and decryption.
- AhnLabAhnLab is a prominent South Korean cybersecurity company specializing in antivirus software, network security, and threat intelligence services.
- AIXAIX (Advanced Interactive eXecutive) is a Unix operating system developed by IBM, primarily used on servers and high-end workstations. It is tracked as a target platform in the context of security vulnerabilities.
- AJAXAJAX is a web development technique that allows web pages to communicate with a server asynchronously without requiring a full page reload. It enables the creation of faster and more dynamic user interfaces.
- ANGLEANGLE is an open-source graphics abstraction layer developed by Google that translates WebGL content to the platform's native graphics APIs to improve performance. In this context, it is mentioned in relation to vulnerabilities in the Chrome browser.
- APIAPI (Application Programming Interface) is a set of defined rules that enable different software applications to communicate with each other. In cybersecurity, APIs are used for data exchange but can also become a significant attack vector if improperly configured.
- APIsAPIs (Application Programming Interfaces) are a set of defined rules and protocols that allow different software components to communicate and exchange data with each other.
- AppSecAppSec (Application Security) is the practice of securing software applications by identifying, fixing, and preventing vulnerabilities throughout their design, development, and deployment lifecycle.
- APTAPT (Advanced Persistent Threat) is an organized hacker group, often state-sponsored, that covertly infiltrates a network to steal data over a long period.
- ASECASEC (AhnLab Security Intelligence Center) is the threat research and analysis division of South Korean cybersecurity firm AhnLab, publishing reports on malware, attacks, and threat actors.
- attack surfaceThe sum of all physical and digital points where a hacker can try to enter a system or extract data.
- ATTACKSMalicious activities targeting computer systems, networks, or data, aiming to cause unauthorized access, damage, or disruption.
- AWSAWS (Amazon Web Services) is a comprehensive cloud computing platform provided by Amazon, offering a variety of IT infrastructure services.
- AXE6600MSI Radix AXE6600 is a high-performance home/gaming router model supporting the Wi-Fi 6E standard; this name appears in our archive to identify the specific hardware at risk.
B8
- B2BB2B (Business-to-Business) – a type of technology platform or integration that enables the digital exchange of data, transactions, or services between companies. This term is commonly used in supply chain and file transfer solutions.
- backupA backup is a second copy of your data allowing you to restore files in case of deletion, loss, or a ransomware attack.
- BC-FJABC-FJA stands for "Bouncy Castle for Java," a widely-used open-source cryptographic library for the Java platform. It provides a comprehensive set of APIs for encryption, digital signatures, and other security protocols.
- BMCA Baseboard Management Controller (BMC) is a specialized microcontroller embedded on a server motherboard that enables remote management, monitoring, and recovery operations independently of the main operating system.
- BO“BO” (Buffer Overflow) is a critical software vulnerability that occurs when a program writes more data to an allocated memory buffer than it is designed to hold.
- botnetA network of infected computers controlled remotely by a hacker, often used for large-scale attacks.
- brute forceBrute force is a cracking method that tries every possible password combination sequentially until finding the correct one.
- BUGAn error or flaw in software or hardware code that causes unexpected behavior, malfunctions, or security vulnerabilities.
C37
- C2The hidden server an attacker uses to send commands to infected devices and maintain control.
- CAA Certificate Authority (CA) is a trusted entity that issues digital certificates and validates their authenticity. It is the cornerstone of the Public Key Infrastructure (PKI), ensuring trusted communication over the internet.
- CAPTCHACAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) is a challenge-response test used on websites to determine whether the user is a human or a bot.
- CDCD (Continuous Delivery) is a software practice where code changes are automatically tested and prepared for release to production.
- CEIn the context of GitLab, CE (Community Edition) refers to the free, open-source, community-supported version of GitLab.
- CERTA Computer Emergency Response Team (CERT) is an organization or team responsible for preventing, detecting, and responding to cybersecurity incidents. They often serve as a central point of coordination for a specific country, sector, or organization.
- CERT-UAA Computer Emergency Response Team, typically a national-level body established to coordinate responses to cybersecurity incidents. This specific term refers to Ukraine's national team, which issues warnings and coordinates defense against cyber threats within the country.
- ChatGPTChatGPT is an AI-powered chatbot developed by OpenAI that understands and responds to natural language prompts.
- CIContinuous Integration (CI) — a software development practice where developers frequently merge code changes into a shared repository, triggering automated builds and tests each time.
- CISACISA (Cybersecurity and Infrastructure Security Agency) is the U.S. federal agency responsible for cybersecurity and protecting critical infrastructure.
- CISOCISO (Chief Information Security Officer) is a senior-level executive responsible for an organization's information security strategy, policies, and operations.
- CISOsCISO (Chief Information Security Officer) – the senior-level executive responsible for an organization's information security strategy, policies, and operations.
- ClamAVClamAV is an open-source antivirus engine widely used for detecting malware at the network and file system level, especially in email gateways and for scanning file uploads.
- CLICLI (Command Line Interface) is a type of user interface that allows users to interact with an operating system or software by typing text commands.
- CMSA CMS (Content Management System) is a software platform used to create, manage, and modify website content without requiring technical knowledge.
- CNAAn organization authorized to assign CVE Identifiers to vulnerabilities within a specific product or research scope in the Common Vulnerabilities and Exposures program, such as vendors like Microsoft or research groups like CERTs.
- code injection"Code Injection" is a security vulnerability that allows an attacker to introduce and execute malicious code within a software application, typically due to improper validation of user input.
- COMWhile COM can refer to a serial port or Microsoft's Component Object Model, in threat intelligence contexts it typically just represents the .com top-level domain extension.
- command and controlCommand and Control (C2) is the infrastructure and communication mechanism used by attackers to remotely control compromised systems, issue commands, and exfiltrate data.
- CONIn cybersecurity context, CON is typically shorthand for DEF CON, one of the world's largest annual hacker conventions.
- CONFIGCONFIG refers to configuration files or the set of parameters that define how a system or application operates. In cybersecurity, misconfigurations are a common vulnerability, and malware often stores its operational settings in encrypted CONFIG files.
- CORSCORS (Cross-Origin Resource Sharing) is a browser mechanism that allows controlled access to resources located outside a given domain. A misconfiguration, typically involving overly permissive or dynamically reflected 'Access-Control-Allow-Origin' headers, can lead to unauthorized cross-domain access to sensitive data.
- CPSDCPSD is the acronym for 'CryptoPro Secure Disk,' representing a software component used for disk encryption integrated with BitLocker.
- CPUCentral Processing Unit (CPU) — the primary hardware component of a computer that executes instructions and processes data.
- CRCR (Carriage Return) is one of two characters sent by the "Enter" key; it is a control character that returns the cursor to the beginning of the line. In web security, if not filtered in HTTP headers, it can lead to attacks like HTTP response splitting.
- credential stuffingAn automated attack that tests leaked usernames and passwords on many sites, exploiting password reuse habits.
- CRMCRM (Customer Relationship Management) is a software system or strategy used by organizations to manage interactions and data with current and potential customers.
- cross-site scriptingA type of web security vulnerability that allows an attacker to inject malicious scripts into a benign website, which are then executed in a victim's browser.
- CRPxOCRPxO is a ransomware group that exfiltrates confidential data and pressures victims by publishing their information on a dedicated leak site.
- cryptojackingThe secret unauthorized use of someone's computer, phone, or server to mine cryptocurrency.
- CSRFCSRF (Cross-Site Request Forgery) is a security vulnerability that allows an attacker to induce an authenticated user to perform unwanted actions on a web application without their knowledge. It exploits the trust a site has in the user's browser to transmit unauthorized commands.
- CSSCSS is a language used to describe the visual presentation and styling of web pages, adding styles like colors, fonts, and layout to documents structured with HTML.
- CSVCSV (Comma-Separated Values) is a simple text file format using commas to separate values, commonly used for storing and exchanging tabular data. In cybersecurity contexts, attackers can exploit CSV injection vulnerabilities to embed malicious formulas or scripts.
- CVECVE (Common Vulnerabilities and Exposures) is a unique identifier given to publicly known software security flaws.
- CVEsCVE, which stands for Common Vulnerabilities and Exposures, is a standardized system that assigns unique identifiers to publicly known cybersecurity vulnerabilities.
- CVSSCommon Vulnerability Scoring System, a standard framework for rating the severity of security vulnerabilities from 0 to 10.
- CXFApache CXF is an open-source, fully featured Web services framework that helps build and develop services using frontend programming APIs like JAX-WS and JAX-RS.
D18
- dark webThe anonymous, encrypted part of the internet not indexed by standard search engines, often used for selling stolen data.
- data breachAn incident where sensitive or confidential data is accessed, stolen, or exposed without authorization.
- data exfiltrationThe unauthorized transfer of confidential or sensitive data from an organization's network to an external location controlled by an attacker.
- DBDB – database. An electronic system for storing, managing, and querying structured data.
- Db2Db2 is a relational database management system (RDBMS) developed by IBM, designed to store, manage, and retrieve data. It is widely used for high-performance transaction processing and complex analytical workloads.
- DDoSDDoS is an attack that floods a server with massive fake traffic, making the service unavailable to real users.
- DEEBOTDEEBOT is a series of robotic vacuum cleaners and smart home devices manufactured by ECOVACS Robotics.
- deepfakeSynthetic media where a person's face or voice is replaced with someone else's likeness using artificial intelligence.
- DEFDEF CON is one of the world's largest and oldest hacker conventions, an annual event where cybersecurity researchers, hackers, and industry professionals gather to discuss vulnerabilities.
- DEFCONDEFCON is one of the world's largest and oldest annual hacker conventions where security researchers, government agents, and hackers gather to discuss cybersecurity topics, conduct trainings, and share knowledge.
- DELETEThe DELETE request method is an HTTP method used to remove a specified resource from the server. When security vulnerabilities exist in web applications, unauthorized DELETE requests can allow attackers to delete critical data or user accounts.
- denial of service“Denial of Service” (DoS) is a type of cyberattack aimed at making a server, network, or service unavailable to its legitimate users, typically by overwhelming it with excessive requests.
- DFIRDFIR (Digital Forensics and Incident Response) is a specialized cybersecurity field that focuses on collecting, analyzing digital evidence and recovering systems after cyberattacks occur.
- DLLA Dynamic Link Library (DLL) is an executable file format in Microsoft Windows that contains shared functions and resources used by multiple programs. In security contexts, malware often loads itself into a system by replacing legitimate DLL files through a method called DLL sideloading.
- DMAThe European Union's Digital Markets Act (DMA) is a regulation that imposes a set of rules on large online platforms (“gatekeepers”) to ensure fair competition.
- DNSDNS (Domain Name System) is the phonebook of the internet, translating human-readable domain names (like google.com) into IP addresses that computers use to communicate.
- DOMThe Document Object Model (DOM) is a platform- and language-neutral interface that allows programs and scripts to dynamically access and update the content, structure, and style of a web page.
- DoSDoS (Denial of Service) – a type of attack that makes a system, network, or service unavailable to legitimate users by overwhelming it with excessive traffic or causing a malfunction.
E10
- ECSElastic Common Schema (ECS) is a standardized data schema defined by Elastic to normalize security event data from diverse sources into a unified format for easier searching and analysis.
- EDRA security tool that continuously monitors endpoint devices and automatically responds to threats, smarter than a basic antivirus.
- EE“EE” stands for “Enterprise Edition” and refers to the paid, commercial version of GitLab designed for large organizations, offering additional functionality and support.
- encryptionEncryption is the process of scrambling your data into unreadable code that can only be decoded with the correct key.
- ePAePA (elektronische Patientenakte) is a German digital infrastructure for electronic health records that allows patients and healthcare providers to store, manage, and securely share medical information. It facilitates the interoperable exchange of health data across different medical facilities.
- EPSSExploit Prediction Scoring System, estimating the probability in percent that a vulnerability will be exploited soon.
- ERPNextERPNext is an open-source, web-based Enterprise Resource Planning (ERP) system built on the Frappe framework. In our threat intel archive, we typically track its vulnerabilities, such as SQL injection and improper authorization flaws, which can lead to unauthorized data exposure.
- ESETESET is a well-known cybersecurity company based in Slovakia, primarily recognized for its antivirus products, threat intelligence, and research.
- ESRESR (Extended Support Release) – A software release channel, particularly for browsers like Firefox and Thunderbird, that receives only security and critical bug fixes over an extended period compared to standard releases.
- EXCLEXCL (Exclusive) is a signal or command in communication protocols or system logs indicating that only one party has access rights to a specific resource. It ensures that the data is not modified by other processes during parallel processing.
F14
- FBIThe FBI (Federal Bureau of Investigation) is the primary federal law enforcement agency of the United States, handling cybercrime, counterintelligence, and counterterrorism investigations.
- FFmpegFFmpeg is an open-source command-line tool used for recording, converting, and streaming multimedia files. It supports a wide range of audio and video codecs and forms the basis for many media applications.
- FHIRFHIR (Fast Healthcare Interoperability Resources) is an HL7 international standard for exchanging healthcare information electronically, enabling API-based communication between systems.
- FIPSFIPS (Federal Information Processing Standards) is a set of technical standards, primarily mandatory for the U.S. government, that define security requirements for cryptographic modules. For instance, the Bouncy Castle library for Java offers a FIPS-certified module, meaning vulnerabilities (CVEs) found in those versions can directly impact the security of FIPS-approved cryptographic operations.
- firewallA firewall is a digital barrier between your network and the outside internet that blocks unauthorized access.
- FreeRDPFreeRDP is a free, open-source, cross-platform implementation of the Microsoft Remote Desktop Protocol (RDP), providing client, server, and library components for remote desktop connections.
- FSPFixed Service Processor (FSP) – An embedded microcontroller within IBM Power Systems responsible for core hardware management functions such as booting, cooling, and system monitoring.
- FTPFTP (File Transfer Protocol) is a standard network protocol used to transfer files between computers over a network. It typically operates in a client-server model for uploading or downloading files.
- FUXAFUXA is a web-based SCADA, HMI, and dashboard software used for process visualization and control in industrial environments. It allows operators to monitor and manage industrial processes through a browser interface.
- FW106FW106 is an identifier for a specific firmware version released for IBM Power Systems servers, typically indicating an update package for certain hardware components.
- FW1060FW1060 is a specific firmware version series used by IBM for certain hardware and software products such as OpenBMC and PowerVM Hypervisor.
- FW1110FW1110 is an identifier indicating a specific firmware release line for IBM platforms such as OpenBMC and PowerVM Hypervisor.
- FW1120A specific firmware release version for IBM Power Systems server hardware. This version identifier is used in threat intelligence reports to pinpoint affected systems for vulnerability management and patching.
- FW950FW950 is a firmware version for IBM Power Systems servers. It represents a specific release of low-level code that controls hardware components.
G14
- GBGB (Gigabyte) is a unit of digital information storage capacity, approximately equal to one billion bytes.
- GETThe primary HTTP method used to request a specific resource (like a web page or image) from a server. It is commonly used to send data by appending parameters to the end of a URL.
- GIMPGIMP (GNU Image Manipulation Program) is an open-source raster graphics editor. In security contexts, it is often noted for vulnerabilities in its file-processing plugins that can be exploited by attackers.
- GitHubGitHub is a cloud-based platform for collaborative software development and version control. It is primarily used to host Git repositories, track code changes, and run automation tools like CI/CD.
- GitLabGitLab is a web-based DevOps platform used for software development and version control. It provides capabilities for hosting code repositories, tracking changes, and automating continuous integration and delivery (CI/CD) pipelines.
- GNUGNU (GNU's Not UNIX) is a project aiming to create a free and open-source Unix-like operating system and an extensive collection of software. It provides core system utilities and libraries often used with the Linux kernel.
- GPTAn acronym for Generative Pre-trained Transformer, a type of artificial intelligence language model pre-trained on vast amounts of data for tasks like text generation, translation, and question answering.
- GPT-5GPT-5 is a hypothetical or future version of the Generative Pre-trained Transformer AI model developed by OpenAI, a large language model designed for text generation, understanding, and analysis.
- GPUGPU is a specialized processor originally designed for accelerating graphics and video rendering, but in cybersecurity contexts, its parallel processing power is exploited for threats like password cracking, crypto-mining, and cloud-based attacks on shared infrastructure.
- GraphQLGraphQL is a query language and runtime for APIs that allows clients to request exactly the data they need, often analyzed in threat intelligence for exploitation vulnerabilities.
- GRCGRC (Governance, Risk, and Compliance) is a strategic management framework that integrates an organization's governance structures, risk management, and adherence to legal or standard requirements. In cybersecurity, it is widely used to describe areas like policy development, internal audit, and regulatory reporting.
- gRPCgRPC (gRPC Remote Procedure Calls) is an open-source remote procedure call protocol developed by Google, used for fast and efficient communication between modern microservices. It uses Protocol Buffers for data exchange and operates over HTTP/2.
- GTIGGTIG stands for Google Threat Intelligence Group, a cybersecurity intelligence unit within Google that tracks, analyzes, and reports on global cyber threats.
- GUIA type of user interface that allows interaction with electronic devices through graphical icons and visual indicators instead of text-based commands.
H9
- H2H2 is an internal codename or version identifier often referring to a specific firmware release level or branch for IBM Power Systems hardware platforms. In threat-intel reports, it is used to denote the software release affected by or remediating a vulnerability.
- H3CH3C is a Chinese multinational technology company that manufactures networking equipment (routers, switches, wireless access points) and digital solutions.
- HCLHCL (Hindustan Computers Limited) is an Indian multinational information technology company that provides software and services. It appears in bulletins reporting vulnerabilities in specific products such as 'HCL Connections'.
- HDF5HDF5 (Hierarchical Data Format version 5) is a file format and library for storing complex scientific data. It is tracked in threat intelligence due to vulnerabilities within this library that are triggered when processing specially crafted HDF5 files.
- HMIHMI (Human-Machine Interface) is a graphical user interface that allows operators to visually monitor and control industrial equipment, serving as a critical component of SCADA systems.
- honeypotA decoy system intentionally set up to lure and trap hackers to study their tactics.
- HTMLHTML (HyperText Markup Language) is the standard markup language for creating the structure of web pages; in cybersecurity, improper handling of HTML can lead to injection attacks such as XSS.
- HTTPHTTP (Hypertext Transfer Protocol) is an application-layer protocol for transmitting hypermedia documents, such as HTML, between web browsers and servers. It is the foundation of data communication for the World Wide Web.
- HTTPSHTTPS is the secure version of HTTP that encrypts data transfer over the internet, ensuring privacy and integrity between a website and a browser.
I19
- IAMIAM is a cloud security service that defines who (identity) can do what (management) to which resource (access); it controls access for people and services to accounts, especially in AWS, through roles, policies, and permissions.
- IBMIBM is a multinational technology and consulting corporation, frequently referenced in cybersecurity contexts for vulnerabilities in its software products and its annual data breach reports.
- ICSICS (Industrial Control Systems) are hardware and software systems used to monitor, control, and automate industrial processes and critical infrastructure such as energy, water, manufacturing, and transportation. Encompassing sub-components like SCADA, PLCs, and DCS, cyberattacks against these systems can lead to physical damage, operational shutdown, and widespread service disruptions.
- IDORIDOR (Insecure Direct Object Reference) is an access control vulnerability where a user can directly reference an internal object (like a file or database record) by its identifier, bypassing authorization checks. An attacker can simply change the identifier value to view, modify, or delete other users' data.
- IDsAn Intrusion Detection System (IDS) is a security tool that monitors network or system activities for malicious actions or policy violations.
- incident responseStructured approach for handling and mitigating the impact of a cyberattack or data breach after it occurs.
- infostealerMalware type designed to harvest credentials, financial data, and other sensitive information from infected systems.
- initial accessIn cybersecurity, "initial access" refers to the stage where a threat actor first gains a successful foothold into a target system or network, typically achieved through methods like phishing, vulnerability exploitation, or credential theft.
- IOInput/Output — the essential communication mechanism that facilitates data transfer between a computer system and its peripheral devices. It allows the processor to interact with external hardware through memory addresses or dedicated ports.
- IOCA piece of digital evidence like a suspicious IP, file hash, or domain that indicates a network or device has been compromised.
- IOSCisco's proprietary operating system used on their routers and switches, standing for Internetwork Operating System.
- IoTThe Internet of Things (IoT) is a network of physical devices, appliances, and sensors embedded with electronics and software to connect and exchange data over the internet.
- IP“IP” (Internet Protocol) is the principal set of rules for addressing and routing data packets across computer networks. Each device on a network is assigned a unique IP address.
- iPadOSiPadOS is an operating system developed by Apple specifically for its iPad tablets, based on iOS but enhanced with tablet-optimized features like Split View multitasking and Apple Pencil support.
- IPsInternet Protocol addresses – unique numerical identifiers assigned to each device on a network that allow them to communicate with each other.
- IPv4IPv4 stands for Internet Protocol version 4, a 32-bit numeric label used to address devices on a network. It is written in a four-part dotted-decimal format (e.g., 192.168.1.1).
- IPv6IPv6 (Internet Protocol version 6) is the most recent network protocol for addressing devices on the internet, providing a vastly larger address space to overcome the address exhaustion problem of its predecessor, IPv4.
- ISCISC (Internet Storm Center) is a program of the SANS Technology Institute that provides daily global threat intelligence and analysis summaries.
- ISOISO is the abbreviation for the International Organization for Standardization, referring to international standards used in various contexts such as product security governance, network protocol layers (the Presentation layer in the OSI model), or file formats (disc images).
J4
- JFrogJFrog is a software company and platform widely used for managing the software supply chain, storing binary files, and automating DevOps processes, with its core product Artifactory serving as a universal repository manager.
- JSJavaScript – a programming language used to create interactive elements, logic, and complex functionality on web pages. This abbreviation is commonly used when referring to JavaScript-based plugins, libraries, or files.
- JSONJSON (JavaScript Object Notation) is a lightweight, human-readable data-interchange format using key-value pairs to structure data. It is commonly used for transmitting data between a server and a web application, as well as for configuration files.
- JWTJSON Web Token is a compact, self-contained token in JSON format used for securely transmitting information between two parties, ensuring integrity and authentication.
K4
- K3"K3" in our archive context refers to the "Kimi K3" AI agent system developed by China's Moonshot AI—a multi-agent platform used by security researchers to autonomously discover and exploit zero-day vulnerabilities.
- KEVKnown Exploited Vulnerabilities catalog by CISA listing actively exploited flaws requiring immediate patching.
- keyloggerA tool that records every keystroke on a device to steal passwords, credit card numbers, and other secrets.
- KVMKVM (Kernel-based Virtual Machine) is a virtualization technology built into the Linux kernel that turns the physical server into a hypervisor to run multiple isolated virtual machines.
L7
- lateral movementThe technique of an attacker moving stealthily from one compromised system to another within a network to reach the main target.
- LDAPLDAP (Lightweight Directory Access Protocol) is a standard protocol used to query and manage directory services, such as Active Directory, over a network.
- LiteLLMLiteLLM is an open-source proxy server and library that provides a unified API interface for various large language models (LLMs). This tool allows applications to call multiple LLM providers using a single, consistent format.
- LLMLLM (Large Language Model) is an artificial intelligence system trained on massive text datasets using deep learning to understand and generate human-like text.
- LLMsLLMs (Large Language Models) are advanced AI models trained on massive datasets to understand and generate human-like text and code.
- LMSLMS (Learning Management System) is a software platform used for creating, managing, delivering, and tracking web-based training courses, educational materials, and online learning processes.
- LTSLTS (Long Term Support) is a software lifecycle support model where a specific version receives security patches and bug fixes from the vendor for an extended period, ensuring stability for end-users.
M17
- M1A high-performance ARM-based system-on-a-chip (SoC) architecture designed by Apple for their Mac computers and iPad Pro tablets.
- MaaSMaaS (Malware-as-a-Service) is an illicit business model where cybercriminals sell or rent out malware, its infrastructure, and support services on a subscription basis. This service allows individuals with low technical skills to launch sophisticated cyberattacks.
- macOSmacOS is the operating system developed by Apple for Mac computers. In cybersecurity, it is analyzed as a platform targeted by threat actors deploying malware to steal information, install backdoors, or exploit system vulnerabilities.
- malwareMalware is any software like viruses or trojans designed to damage a computer or gain unauthorized access.
- man-in-the-middleA man-in-the-middle (MITM) attack is a type of cyberattack where an attacker secretly intercepts and potentially alters the communication between two parties who believe they are directly communicating with each other.
- MBMB (Megabyte) is a unit of digital information used to measure computer memory or file size, approximately equal to one million bytes.
- MCPMCP (Model Context Protocol) is an open protocol designed to enable AI models to securely and standardly connect with external data sources and tools, allowing AI agents to share context with various systems.
- MDRManaged Detection and Response (MDR) is a cybersecurity service that outsources security operations, where a provider offers technology and expertise to detect, analyze, and respond to threats.
- MFAMFA (Multi-Factor Authentication) is an extra security layer requiring a second verification, like an SMS code, besides your password.
- MIMEMIME is an extension standard of the email protocol that allows sending different types of files such as text, images, audio, and video within a single message.
- MITMMan-in-the-Middle – an attack where the threat actor secretly intercepts and relays or alters communication between two parties; used in the archive to describe the attacker’s position.
- MITRE ATT&CKOpen knowledge base of adversary tactics and techniques derived from real-world cyber threat observations.
- MongoDBMongoDB is a document-oriented, highly scalable NoSQL database system that uses BSON-formatted records instead of traditional table structures.
- MOVEitMOVEit is a managed file transfer (MFT) software used by enterprises for secure transfer of sensitive data. Particularly its "MOVEit Transfer" and "MOVEit Cloud" products are frequently targeted in cyberattacks due to critical vulnerabilities.
- MSMS stands for Microsoft; in threat intelligence, it often refers to Microsoft's security products or services, such as MS Purview for data loss prevention.
- MSIMSI (Microsoft Installer) is a package format and service in Windows used for installing, maintaining, and removing software. In security contexts, MSI files are often abused to deliver malware or escalate privileges.
- MySQLMySQL is an open-source relational database management system widely used for web applications and servers. It uses SQL for storing, managing, and querying structured data.
N8
- NCSCThe NCSC (National Cyber Security Centre) is the United Kingdom's national authority for cybersecurity, responsible for defending the country against cyber threats, coordinating incident response, and publishing security guidance.
- NET.NET is a software development framework and runtime environment created by Microsoft that supports multiple programming languages and primarily runs on Windows.
- NFCNFC (Near Field Communication) is a short-range wireless technology that enables data exchange between devices within a few centimeters, often used in security contexts for contactless payments, access control, or data relay attacks.
- NISTThe National Institute of Standards and Technology, a U.S. agency that develops global guidelines and standards for cybersecurity frameworks, encryption standards, and vulnerability management.
- NLnetNLnet is a Dutch non-profit foundation supporting internet research and standards development, most commonly known in cybersecurity contexts for its subsidiary NLnet Labs, the developer of DNS server software such as Unbound.
- NPMNPM is the default package manager and online registry for the JavaScript programming language, allowing developers to share and download open-source code libraries.
- NULLNULL is a special pointer value in programming that points to no memory address. Dereferencing a NULL pointer can create a security vulnerability leading to a program crash or arbitrary code execution.
- NX15NX15 is the trade name for a specific wireless router model manufactured by H3C.
O11
- OAuthOAuth is an open-standard authorization protocol that allows users to grant limited access to their data on one service to a third-party application without sharing their password.
- OAuth2OAuth2 is a standard authorization protocol that allows applications to grant limited access to a user's data without sharing their passwords with third-party services.
- OCSPOCSP (Online Certificate Status Protocol) is a protocol used to check the validity status (e.g., revocation) of a presented digital certificate in real-time, ensuring TLS/SSL connection security.
- OIDCOIDC (OpenID Connect) is an authentication layer built on top of the OAuth 2.0 protocol, used to verify user identities and obtain basic profile information. It provides an ID Token to the client, confirming the user's identity for secure login.
- OpenAIOpenAI is a technology company focused on artificial intelligence research and deployment, known for developing widely-used models such as ChatGPT. In a security context, its name frequently appears in reports concerning novel vulnerabilities in AI systems, malicious agents, or incidents involving research labs.
- OpenAPIOpenAPI is a standard specification for describing RESTful APIs, allowing both humans and machines to understand the capabilities of a network service without accessing its source code. In security contexts, misconfigured OpenAPI specifications frequently expose sensitive API structures.
- OSOS, or Operating System, is the foundational software that manages computer hardware resources and provides common services for application software. In cybersecurity, OS command injection vulnerabilities allow an attacker to execute arbitrary commands at the operating system level on the target system.
- OSSOSS (Open Source Software) – software with publicly accessible source code that can be used, modified, and shared by anyone.
- OTOT (Operational Technology) refers to hardware and software systems that directly monitor and/or control physical devices, processes, and infrastructure, such as industrial control systems (ICS) and SCADA.
- OTPOTP (One-Time Password) is a temporary code valid for a single login or transaction. However, in the provided archive examples, "OTP" refers to "Open Telecom Platform," a collection of libraries for building distributed, fault-tolerant systems in the Erlang programming language.
- OWASPOWASP (Open Web Application Security Project) is a non-profit foundation that provides free resources, tools, and standards to improve the security of web application software.
P24
- P2PP2P (Peer-to-Peer) – a decentralized network architecture where nodes communicate and share resources directly without relying on a central server, with each participant acting as both a client and a server.
- PaaSPlatform as a Service (PaaS) is a cloud computing model that provides a ready-made environment for users to develop, deploy, and manage software without building the underlying infrastructure.
- patchA patch is a small piece of code released to close security holes found in a software.
- patch managementSystematic process of acquiring, testing, and applying updates to fix security holes in operating systems and software.
- PATHPATH: An environment variable that lists directories where the operating system searches for executable files. In a security context, misconfiguration or manipulation of this variable can lead to attacks like DLL Search Order Hijacking.
- payloadThe part of malware that performs the malicious action, such as encrypting files or stealing data.
- PayPal“PayPal” is an international online payment system and digital wallet that allows users to send, receive money and conduct commercial transactions over the internet.
- PDFPDF (Portable Document Format) is a file format created by Adobe for document exchange, which preserves text, images, and vector graphics in their original layout independently of the platform.
- PDUA Protocol Data Unit is a unit of data specified in a protocol of a given layer of the OSI model, which contains protocol-control information and possibly user data. For example, at the Data Link Layer, the PDU is often referred to as a frame.
- penetration testingAn authorized simulated cyberattack on a system to find security weaknesses before real attackers do.
- phishingPhishing is a deceptive attack disguised as a trusted entity to trick you into revealing sensitive data like passwords or card details.
- PHPPHP is a widely used server-side scripting language for web development, commonly found in content management systems like Joomla.
- PIIPersonally Identifiable Information (PII) is any data that can be used to identify a specific individual, either on its own or when combined with other information.
- PLCsA PLC (Programmable Logic Controller) is a specialized computer used to control machines and processes in industrial environments like water treatment plants and power stations.
- POCProof of Concept – a practical code, script, or demonstration used to verify the existence of a vulnerability, such as the POC for CVE-2026-49176 showing privilege escalation in Windows WalletService.
- POSTOne of the main HTTP methods used to send data to a server. Data such as web form submissions, API requests, or file uploads is typically transmitted within the body of a POST request.
- PowerVMPowerVM is IBM's virtualization technology for POWER processor-based servers, enabling a single physical server to be divided into logical partitions (LPARs) to run multiple operating systems concurrently.
- privilege escalationA technique where an attacker gains higher-level permissions, like administrator access, from an initially low-level compromise.
- PROPRO is an abbreviation for 'Professional' in software licensing, indicating a paid, higher-tier version of a product that offers more advanced features than the basic edition.
- PROSetPROSet is the name for Intel's device driver and management software package for its network adapters, providing the necessary drivers and utilities for wireless connectivity.
- PTCPTC in this context stands for 'Parametric Technology Corporation'; a vendor of product lifecycle management (PLM) and industrial IoT software.
- PUTPUT is an HTTP request method used to update or completely replace an existing resource on a server. In a security context, improperly configured PUT requests can lead to unauthorized modification of data.
- Pwn2OwnPwn2Own is a renowned international hacking competition where elite security researchers compete in real-time to find previously unknown vulnerabilities in popular software and devices. Winners earn cash prizes for their zero-day exploits, which are immediately disclosed to the respective vendor for patching.
- PyPIPyPI (Python Package Index) is the official third-party software repository for the Python programming language, allowing developers to publish and share libraries and modules.
Q1
R18
- RaaSRansomware-as-a-Service (RaaS) is a cybercriminal business model where ransomware operators lease their malware and infrastructure to other criminals on a subscription or revenue-sharing basis. This model enables even individuals with low technical skills to launch sophisticated attacks.
- ransomwareRansomware is malicious software that encrypts your files and demands a ransom for their return.
- Rapid7A well-known American technology company operating in the cybersecurity field, providing services such as vulnerability management, threat detection, and incident response.
- RATMalware that gives an attacker full remote control over a victim's computer, including camera and microphone access.
- RATsRAT (Remote Access Trojan) – a type of malware that provides an attacker with full remote control over an infected system, often used to steal files, capture screenshots, or download additional malware.
- RCERCE (Remote Code Execution) is a critical vulnerability that allows an attacker to execute arbitrary commands or code on a target system over a network. It is considered one of the most dangerous types of attacks, as it can often lead to a full system compromise.
- RDPRDP (Remote Desktop Protocol) is a proprietary protocol developed by Microsoft that allows a user to connect to and control a remote Windows computer over a network with a graphical interface.
- RDWRRDWR is an access flag used in Unix/Linux system calls for file descriptors, indicating the combination of both read and write permissions.
- RECORDIn the context of CVE (Common Vulnerabilities and Exposures), a RECORD is a unique data unit containing all official information about a specific vulnerability or security issue, representing the structured database entry associated with a CVE identifier.
- remote code executionRemote Code Execution (RCE) is a vulnerability that allows an attacker to run arbitrary commands or malicious code on a target system over a network, often leading to full system compromise.
- RESTREST (Representational State Transfer) is a resource-oriented architectural style for web services, where communication between client and server typically occurs over HTTP using formats like JSON or XML.
- RESTfulRESTful refers to web services or APIs that adhere to REST architectural principles, enabling access to resources through standard HTTP methods like GET, POST, PUT, and DELETE.
- RFCAn RFC (Request for Comments) is a formal document that defines Internet standards, protocols, and procedures, serving as the official specification for how network technologies should operate.
- RMMRMM (Remote Monitoring and Management) is a category of legitimate software tools used by system administrators to remotely monitor, manage, and support computers and servers across a network. Threat actors often abuse these tools to maintain stealthy, persistent access within compromised environments.
- rootkitStealthy malware bundle designed to hide its existence and provide unauthorized privileged access to a computer.
- RPCRPC (Remote Procedure Call) is a protocol or communication mechanism that enables one computer program to request and execute a procedure located in a different address space or remote server as if it were a local call, commonly used for service-to-service communication in distributed systems.
- RSARSA is a public-key cryptosystem widely used for secure data transmission and digital signatures, based on the practical difficulty of factoring the product of two large prime numbers.
- RUNThe English verb 'RUN', meaning to execute or launch a program, script, command, or analysis environment (sandbox) in a cybersecurity context; for example, the 'RUN' in the interactive malware analysis service ANY.RUN refers to executing a file in a safe environment.
S36
- S7S7 is a proprietary communication protocol used by Siemens programmable logic controllers (PLCs) to manage industrial equipment, making it a prime target in attacks on critical infrastructure.
- SaaSSaaS (Software as a Service) is a cloud-based delivery model where users access software over the internet on a subscription basis rather than installing it locally. In cybersecurity contexts, SaaS applications are frequent targets for credential theft, OAuth abuse, and misconfiguration attacks.
- SAMLSAML (Security Assertion Markup Language) is an open standard for securely exchanging authentication and authorization data between parties, specifically between an identity provider and a service provider, using XML-based assertions for single sign-on.
- sandboxAn isolated, safe environment used to test suspicious files or software without risking the main system.
- sandboxingSecurity practice of running untrusted code in an isolated environment to prevent harm to the main system.
- SAPSAP (Systems, Applications, and Products) is widely used enterprise resource planning (ERP) and business process management software. In cybersecurity contexts, it typically refers to the critical vulnerabilities discovered in these systems and the security patches applied to address them.
- SCADASCADA (Supervisory Control and Data Acquisition) is a computer system architecture used for monitoring, gathering data, and controlling industrial processes.
- SD-WANSD-WAN (Software-Defined Wide Area Network) is a network technology that enables centralized, software-based management of an organization's various branch and cloud environments. It replaces traditional routers to provide a more flexible, secure, and optimized connectivity.
- SDKSDK (Software Development Kit) is a collection of tools, libraries, and documentation used to create software. It helps developers build applications for a specific platform or service more quickly.
- SEOSEO (Search Engine Optimization) is the practice of improving a website's visibility and ranking in organic search engine results to increase traffic.
- SFTPSFTP (SSH File Transfer Protocol) is a network protocol that securely transfers and manages files over an encrypted SSH connection, unlike standard FTP.
- SIEMA system that collects and analyzes security logs from across the network to detect suspicious activity.
- SIM swapA scam where an attacker tricks a mobile carrier into transferring a victim's phone number to the attacker's SIM card to intercept verification codes.
- SIPSIP (Session Initiation Protocol) – A core signaling protocol used to initiate, manage, and terminate real-time communication sessions like voice, video, and messaging over IP networks.
- SiYuanSiYuan is an open-source, local-first knowledge management and note-taking application that uses a block-based content structure for building personal knowledge bases.
- SMBSMB (Server Message Block) is a network communication protocol used for providing shared access to files, printers, and other resources. It primarily facilitates client-server interactions in Windows environments.
- smishingA phishing attack delivered via text message, containing malicious links or deceptive requests to trick victims.
- SMRSMR (Security Maintenance Release) – An official monthly software update for Samsung mobile devices that patches discovered security vulnerabilities.
- SMSSMS (Short Message Service) is a telecommunications protocol used for sending short text messages between devices over mobile networks. In cybersecurity contexts, it is frequently tracked as a vector exploited for phishing, intercepting multi-factor authentication OTPs, or enabling malware to communicate with command-and-control servers.
- SOARSOAR (Security Orchestration, Automation, and Response) is a platform that integrates various security tools, automates repetitive workflows, and coordinates incident response actions.
- SOCA centralized team that monitors, detects, and responds to cybersecurity incidents in real-time, 24/7.
- social engineeringThe psychological manipulation of people to trick them into giving up confidential information, rather than hacking systems directly.
- SPSP is short for “Space”, a fundamental invisible character used to separate words in text within computer systems, but in security contexts it can enable injection attacks if allowed where not permitted by protocols.
- spear phishingTargeted phishing attack tailored to a specific individual or organization to steal sensitive data.
- spywareSoftware that secretly monitors a user's activity, recording keystrokes, browsing history, and personal data.
- SQLSQL (Structured Query Language) is a standard programming language used for managing and querying databases; in a security context, it is commonly associated with SQL injection vulnerabilities, which allow an attacker to send unauthorized queries to the database.
- SQL injectionSQL injection is a code vulnerability that allows an attacker to inject malicious database commands into a website's input field to extract data.
- SQLiteA compact, serverless, and self-contained relational database management system designed for embedded and resource-constrained environments.
- SSHSSH (Secure Shell) is a cryptographic network protocol used for secure remote login and command execution over an unsecured network. It is often abused by threat actors to create reverse tunnels for malicious purposes.
- SSLSSL (Secure Sockets Layer) is a standard security protocol used to encrypt data transmitted over the internet, establishing a secure connection between a client and a server.
- SSOSSO (Single Sign-On) is an authentication scheme that allows a user to log in with a single set of credentials to access multiple related, yet independent, systems or applications.
- SSRFA Server-Side Request Forgery (SSRF) attack manipulates a vulnerable server into making unauthorized requests on the attacker's behalf, often to access internal network resources or external systems. It typically exploits the server’s ability to fetch or relay data to destinations that are otherwise inaccessible to the attacker.
- supply chainSupply chain refers to the network of third-party vendors, tools, and components involved in creating and delivering software, hardware, or services; an attack on any link in this chain can compromise the final product or organization.
- supply chain attackA tactic that targets a victim by compromising a trusted third-party supplier, service, or software they use.
- SVGSVG (Scalable Vector Graphics) is an XML-based vector image format for the web, which can embed malicious JavaScript code, making it a common vector for phishing and malware attacks.
- SYSTEMSYSTEM is the highest-privileged built-in account in Windows operating systems. When processes run under this context, they have full, unrestricted access at the operating system kernel level.
T11
- TCPTCP (Transmission Control Protocol) is a core network protocol that ensures reliable, ordered, and error-checked data exchange between computers.
- TeamPCPTeamPCP is the designated name assigned by the cybersecurity community to a specific threat actor group, derived from acronyms for tactics such as 'pivoting,' 'credential access,' and 'persistence.' This group is commonly associated with supply-chain attacks targeting open-source software and cloud environments.
- threat actorIndividual, group, or state entity responsible for executing malicious cyber operations.
- threat huntingThreat hunting is a proactive cybersecurity approach for actively searching through networks and systems to find hidden threats or malicious activities that have evaded existing automated security defenses. It involves analysts conducting deep investigations based on hypotheses rather than waiting for alerts to fire.
- threat intelligenceCollected and analyzed information about current and potential cyber threats that helps organizations make informed defense decisions.
- TL“TL;DR” is an internet slang abbreviation for “Too Long; Didn't Read,” used to provide a brief summary of a lengthy text. Additionally, the “TL-” prefix is part of a product model designation, such as in TP-Link devices like the TL-WR940N.
- TLSTLS (Transport Layer Security) is a cryptographic protocol used to encrypt data transmitted over a network and authenticate the communicating parties.
- TOCTOUTOCTOU (Time-of-Check Time-of-Use) is a race condition vulnerability where an attacker exploits the brief gap between a system's check of a resource's state and its actual use, altering the condition in between to bypass security controls.
- TP-LinkTP-Link is a global technology company that manufactures networking equipment such as routers, switches, and access points.
- trojanMalware disguised as legitimate software that tricks users into running it and performs harmful actions secretly.
- tvOStvOS is the operating system developed by Apple specifically for the Apple TV media player device, primarily designed for media streaming, games, and apps.
U7
- UAFA critical memory corruption vulnerability that occurs when a program continues to access a memory location after it has been freed or deallocated.
- UDPUDP (User Datagram Protocol) is a connectionless network protocol used for fast but unreliable data transmission. It is often chosen over TCP in scenarios where speed is prioritized, such as DNS queries.
- UIUI (User Interface) – The visual elements (buttons, menus, windows) through which a user interacts with a computer system.
- URIA URI (Uniform Resource Identifier) is a string of characters that uniquely identifies a resource on the internet or a local system; URLs are its most common type.
- URLURL (Uniform Resource Locator) is a standard format used to specify the address of a resource on the internet, such as a web page, image, or file. It tells a browser or application how to connect to and where to find that resource.
- URLsA URL (Uniform Resource Locator) is a standard format that specifies the address of a resource, such as a web page, image, or file, on the internet.
- USBUniversal Serial Bus – a standard cable interface for connecting peripherals to a computer; in security contexts, it can act as a physical medium for malware delivery.
V8
- V2'V2' is an abbreviation typically denoting the second version (Version 2) of a malware family, cyberattack tool, or threat cluster, indicating significant updates in functionality, tactics, or codebase.
- V8V8 is a high-performance open-source JavaScript and WebAssembly engine developed by Google, used in browsers like Chromium to execute code. It compiles scripts directly into machine code to enable fast web page performance.
- VIOSVIOS (Virtual I/O Server) is a specialized virtualization component within IBM's PowerVM platform. It is designed to share physical I/O resources, such as network and storage adapters, among multiple logical partitions.
- vishingVoice phishing, a social engineering attack using phone calls to trick victims into revealing sensitive information.
- VMA VM (Virtual Machine) is an isolated, software-based computing environment that runs its own OS and applications using the resources of a physical computer, commonly used for malware analysis or targeted by malware to detect sandboxes.
- VMWareVMware is a company that provides virtualization and cloud computing software, widely used for virtualizing servers, networks, and workstations.
- VNCVNC (Virtual Network Computing) is a graphical desktop-sharing protocol that allows a user to remotely control another computer's desktop over a network.
- VPNVPN (Virtual Private Network) is an encrypted tunnel that hides your IP address, making you anonymous online.
W7
- watchOSwatchOS is the operating system developed by Apple for Apple Watch smartwatches. It is based on iOS and is specifically optimized for wrist-worn devices.
- WebUIWebUI is a graphical interface that allows users to control and configure a network device, server, or software application through a web browser. This term commonly refers to the administration panel of routers, access points, or web-based platforms.
- Wi-FiWi-Fi is a wireless networking technology that allows devices to connect to a network and the internet without cables.
- WiFiWiFi is a set of technologies and standards that allow devices to connect to a network wirelessly using radio waves.
- wiperDestructive malware designed to completely erase data on a computer, making it permanently unrecoverable.
- wormSelf-replicating malware that spreads across networks without user interaction, often slowing down systems.
- WP“WP” is a common abbreviation for “WordPress,” a web content management system. In threat intel archives, it's typically used as a prefix to refer to vulnerable plugins built for this platform (e.g., WP Foodbakery).
X4
- XEA network operating system from Cisco that powers many of their enterprise routers and switches, integrating networking, security, and programmability into a single platform.
- XMLXML (Extensible Markup Language) is a flexible markup language designed to encode documents in a format that is both human-readable and machine-readable, commonly used for storing and transporting structured data between disparate systems.
- XSSA vulnerability that lets attackers run malicious scripts in a victim's browser, often to steal cookies.
- XXEAn XML External Entity (XXE) vulnerability is a security flaw where an application insecurely processes XML input, allowing an attacker to access external resources, disclose data, or perform denial-of-service attacks.
Y1
Z4
- ZEBRAZEBRA is an alternative full node implementation for the Zcash cryptocurrency, written entirely in the Rust programming language. It focuses on performance and memory safety, differing from the original Zcash node.
- zero trustA security model based on 'never trust, always verify', requiring continuous validation for every user and device, even inside the network.
- zero-dayA zero-day is an unpatched security hole unknown to the developer, which can be exploited immediately (day zero).
- ZIPZIP is a widely used archive file format that supports lossless data compression, allowing multiple files and directories to be stored in a single container. It reduces file size for efficient storage and transmission.
321 terms · part of skopnix — global cyber-threat intelligence.