This umbrella term refers to any software designed to harm, exploit, or gain unauthorized access to a system.
What is Malware?
This is the button you should click if you suspect an email is suspicious or a positive phishing attempt
These file types are programs that run on your machine
What is an executable file (.exe, .bat, or .cmd)?
This device should be locked whenever you step away, even for a minute.
What is your computer/phone?
This term describes an AI model stating false information withcomplete confidence.
What is a hallucination?
This acronym stands for a security method requiring two or more verification steps to log in.
What is MFA (Multi-Factor Authentication)?
Before clicking a link, you should do this to it to preview where it actually leads.
What is hovering over it?
These file types can contain dangerous scripts that can run code on your browser or on your computer
What are script and web files (.js, .py, .sh, or .html)
The art of manipulating, influencing, and deceiving people for malicious purposes.
What is Social Engineering?
This category of information — think PHI, PII, or financial records —should never be typed into a public AI chatbot.
What is sensitive / confidential data?
This acronym refers to a private, encrypted connection used to protect data over public networks.
What is a VPN (Virtual Private Network)?
This type of language is used to incite fear or panic in phishing to make you click without thinking.
What is urgent or threatening language?
These file types are like a sealed box, you dont know what's inside until you open them up!
What are archive files (.zip or .rar)
This is something everyone can do with content received before clicking hastily.
This practice means a person always checks AI-generated outputbefore it's trusted, sent, or acted on.
What is human review (human-in-the-loop)?
These can be captured by an attacker to log into a website as you by proving your identity after you've already authenticated.
What are Session Cookies?
Even without proof, this is the single best action to take when something about a message or request feels off.
What is reporting it to Cybersecurity?
Attackers commonly use this tactic to hide a file type to make it look innocent like a PDF
What is a double extension? (ex: Invoice.pdf.exe)
This habit — updating software, OS, and apps regularly — closes known security holes before attackers can exploit them.
What are security patches?
Public models (like ChatGPT, Claude, or Gemini) may use inputs and turn it into this which makes unique phrasing or data points part of the model's collective knowledge.
What is Training Data?
This threat comes from someone within an organization — an employee, contractor, or partner — who misuses their access.
What is an insider threat?
This type of attack impersonates a high-level executive to trick employees into wiring money or buying gift cards.
What is CEO fraud (Business Email Compromise)?
This is a verification step you can take to confirm the email you received actually came from the sender address that is marked on the email
What is confirm with the sender using a different method of communication? (ex: if you received the message as an email reach out to them via text or teams)
This term describes attackers researching a target's social media and public info before an attack.
What is OSINT (open-source intelligence gathering)?
This is what happens when AI is tricked into generating harmful content, such as phishing templates or malicious code, that it would normally refuse to write.
What is weaponization?