Digital Security Glossary

Learn the essential terms to understand cyber threats and protect your accounts. From A to Z.

A security method requiring two forms of verification to access an account: something you know (password) and something you have (phone code, physical key or authenticator app). Significantly increases protection against intrusions.

A secret entry point in a system or software that allows unauthorized access, bypassing normal authentication mechanisms. Can be intentionally inserted by malicious developers or exploited by hackers.

An attack that tries all possible password combinations until finding the correct one. Short, simple passwords are vulnerable. Use long passwords (12+ characters) with letters, numbers and symbols to protect yourself.

A test that distinguishes humans from bots, usually displaying distorted images or challenges that machines have difficulty solving. Protects websites against automated attacks such as spam and brute force.

The process of encoding information so that only authorized recipients can read it. Encrypted data is transformed into an unreadable format without the correct key. Essential for protecting communications and sensitive data.

An attack that overwhelms a server or network with massive traffic from multiple sources, making the service unavailable to legitimate users. Uses networks of infected devices (botnets) to amplify the attack.

Psychological manipulation to induce people to reveal confidential information or take actions that compromise security. Includes phishing, pretexting and baiting. Human error is exploited rather than technical vulnerabilities.

A security system that monitors and controls network traffic between networks (internet and local network) based on defined rules. Blocks unauthorized access while allowing legitimate traffic.

A mathematical function that transforms data of any size into a fixed-length string of characters (hash). It's one-way — you can't reverse the hash to get the original data. Used to store passwords securely.

Software or hardware that records every keystroke typed by the user, including passwords and sensitive data. Can be installed via malware or physically on keyboards. One of the main threats for credential theft.

A general term for malicious software: viruses, trojans, ransomware, spyware, etc. Designed to damage systems, steal data or gain unauthorized access. Installed via downloads, email attachments or exploits.

A fraud technique that impersonates legitimate entities (banks, social networks) to trick victims into revealing passwords, banking data or personal information. Uses emails, messages and fake pages identical to the originals.

Malware that encrypts the victim's files and demands payment (ransom) to release access. There's no guarantee of recovery even after paying. Prevention through backups and updated software is essential.

A scam where the attacker convinces the carrier to transfer the victim's phone number to a new SIM card in their possession. Allows interception of SMS 2FA codes and account takeover. Use app-based authenticators when possible.

Software that secretly monitors user activities — keystrokes, websites visited, messages — and sends the data to the attacker. Can be installed via malicious apps or as part of legitimate software.

Encryption protocols that protect communication between browser and server. The padlock in the address bar indicates a secure connection. Essential for protecting data in transit (passwords, card details).

A temporary credential used for authentication. Can be a numeric code (like in authenticator apps), a physical device (security key) or a digital string. Tokens expire after use or a defined time.

Malware that disguises itself as legitimate software to deceive the user. Once installed, it opens doors for the attacker, steals data or installs other malware. Named after the Greek myth of the Trojan Horse.

An encrypted connection that creates a secure tunnel between your device and the internet. Hides your real IP, protects data on public Wi-Fi networks and allows more private browsing. Choose trusted providers.

A software vulnerability that is exploited before the developer becomes aware or has time to fix it. "Zero day" refers to the fact that no patches are available. Extremely valuable to attackers.