Cyber Threats Reference: Key Terms and Attack Types Defined
Photo credit: Telecom360.net | Connecting You To The Latest In Telecom
A plain-language glossary of the most common cyber threat terms — from adware to zero-day — for quick lookup when you encounter unfamiliar jargon.
How to Use This Reference
Cybersecurity reporting is full of terminology that can feel opaque — even to people who use smartphones and computers every day. This reference compiles the most frequently encountered cyber threat terms in a single, plain-language lookup guide. Use it alongside deeper reads like Digital Threats Every Smartphone User Should Know About when you need fuller context on how these attacks actually work in practice.
Entries are organized into two sections: attack types (techniques attackers deploy against you) and malware categories (malicious software classified by behavior). Each definition prioritizes what the threat does and why it matters to you as a device user.
| Most common entry vector | Phishing emails and malicious links (CISA Cybersecurity Advisory, 2023) |
| Average ransomware downtime | 21 days (Coveware Quarterly Ransomware Report, 2023) |
| Password reuse rate among users | ~65% (Google/Harris Poll survey findings) |
| Zero-day exploits discovered annually | 70+ (documented) (Google Project Zero annual tracking data) |
| DDoS attacks mitigated per day (major providers) | Thousands (Cloudflare DDoS Threat Report, 2023) |
Attack Types Defined
Understanding attack types helps you recognize how a compromise begins — before malware ever reaches your device.
Terminology Evolves Quickly
Cyber threat categories are not rigid — attackers constantly combine techniques. A single attack may use phishing to deliver spyware that also functions as a keylogger, for example. Understanding how terms overlap helps you recognize hybrid threats rather than expecting neat categories.
- Phishing
- Deceptive messages — typically email, SMS (smishing), or voice calls (vishing) — designed to trick you into surrendering credentials or clicking a malicious link. Spear phishing is a targeted variant using personalized details to appear more credible.
- Man-in-the-Middle (MitM)
- An attacker positions themselves between two communicating parties — often by exploiting unsecured public Wi-Fi — to intercept or modify data in transit without either party's knowledge.
- Credential Stuffing
- Automated use of stolen login pairs across multiple sites. Password reuse makes this attack highly effective and is why security guidance consistently recommends unique passwords per service.
- DDoS (Distributed Denial-of-Service)
- Large volumes of traffic, sourced from botnets, overwhelm a service until it becomes unreachable. Individuals are rarely direct targets, but service outages affect everyone using the platform.
- Zero-Day Exploit
- Attackers weaponize an unpatched vulnerability before the software vendor knows it exists. Applying updates promptly closes known vulnerabilities and limits exposure to older, patched flaws.
83%
Organizations hit by phishing in a given year
According to Proofpoint's State of the Phish report, the vast majority of organizations experience at least one successful phishing attempt annually.
~$4.45M
Average cost of a data breach
IBM's Cost of a Data Breach Report 2023 placed the global average cost of a corporate data breach at $4.45 million.
94%
Malware delivered via email
Verizon's Data Breach Investigations Report consistently identifies email as the dominant delivery mechanism for malware payloads.
Malware Categories Defined
Malware is a broad term for any software designed to harm, exploit, or gain unauthorized access. Different families behave in distinct ways, and knowing the distinctions matters for understanding risk. For a full picture of how malware threatens your specific devices, see Device Security Across Your Digital Life.
- Ransomware
- Encrypts your files and demands payment for the decryption key. Organizations and individuals alike are targeted. Offline backups are widely recommended as the primary mitigation.
- Spyware & Keyloggers
- Spyware silently monitors activity — location, camera, messages — while keyloggers specifically capture keystrokes to harvest passwords and financial data. Both exfiltrate data to attackers without visible symptoms.
- Rootkits
- Operate at a deep system level to conceal themselves and other malicious payloads from antivirus tools. Rootkits are among the most difficult infections to detect and remove.
- Adware & Potentially Unwanted Programs (PUPs)
- Often bundled with free software, adware injects ads and may collect behavioral data. While frequently treated as a nuisance, aggressive adware crosses into spyware territory.
- Botnets
- Your device may be enrolled in a botnet without any noticeable performance change. Botnet membership is typically detected through network traffic analysis rather than device symptoms.
Adware
Software that displays unwanted advertisements, often bundled with free applications. While not always malicious, adware can track browsing behavior and degrade device performance.
Botnet
A network of internet-connected devices infected with malware and remotely controlled by an attacker, often used to send spam, launch DDoS attacks, or mine cryptocurrency without the owner's knowledge.
Credential Stuffing
An automated attack in which stolen username-password pairs from one breach are tried against other services, exploiting users who reuse passwords across multiple accounts.
DDoS (Distributed Denial-of-Service)
An attack that floods a server or network with traffic from many sources simultaneously, making the targeted service unavailable to legitimate users.
Exploit
A piece of code or technique that takes advantage of a software vulnerability to cause unintended behavior, such as gaining unauthorized access or executing malicious commands.
Keylogger
Malicious software or hardware that records every keystroke made on a device, enabling attackers to capture passwords, credit card numbers, and other sensitive input.
Man-in-the-Middle (MitM)
An attack in which an adversary secretly intercepts and potentially alters communications between two parties who believe they are talking directly to each other.
Phishing
A social engineering attack delivered via email, text, or other messaging that deceives recipients into revealing credentials, clicking malicious links, or downloading harmful files.
Ransomware
Malware that encrypts a victim's files or locks their device and demands payment — typically in cryptocurrency — for the decryption key or restored access.
Rootkit
A class of malware designed to conceal its presence and grant persistent, privileged access to a system, often hiding other malicious software from security tools.
Spyware
Software that covertly monitors device activity — including location, messages, and camera access — and transmits the collected data to a third party without user consent.
Zero-Day
A software vulnerability that is unknown to the vendor and has no available patch; attackers who discover zero-days can exploit them before any defense is in place.
For additional technical terminology outside the security domain, A Practical Glossary of Mobile OS and App Terms covers software and operating system vocabulary you may encounter when reading about smartphones.
