Glossary
The language of security, explained briefly and precisely, from pentest to zero-day.
- CVECVE stands for Common Vulnerabilities and Exposures: unique identifiers for publicly known security flaws. Learn how CVE IDs work and where to look them up.
- CVSSCVSS scores vulnerabilities from 0.0 to 10.0. Learn how the base score is built up, how v3.1 and v4.0 differ, and why a score is not a risk rating.
- MFA (multi-factor authentication)MFA asks for a second factor alongside the password. Why SMS and push are the weak options and why FIDO2 and passkeys resist phishing.
- PentestA penetration test (pentest) is a controlled attack on your systems by ethical hackers. Learn how a pentest works and what vulnerabilities it uncovers.
- PhishingPhishing is an attack in which criminals impersonate a trusted party to obtain credentials, payments or access. Here is how it works and how to stop it.
- RansomwareRansomware explained: how this malware encrypts files and systems, how attacks get in, and how to protect your organisation from digital extortion.
- Red teamingRed teaming is a goal-driven attack simulation that tests whether your defenders notice. Learn how it differs from a pentest and what TIBER-EU involves.
- Responsible disclosureResponsible disclosure means reporting a vulnerability privately so the organisation can fix it before any details are made public. Here is how it works.
- Social engineeringSocial engineering attacks the person instead of the system. How pretexting, urgency and help-desk resets work, and the process that stops them.
- Zero-dayA zero-day is a vulnerability still unknown to the vendor, meaning no patch exists yet. Learn how zero-day exploits work and how to limit the risk they pose.