Essential terms in AI cyber security, threat intelligence, and defensive cyber intelligence. Use this glossary to understand the language of modern cyber threats and defenses.
AI Cyber Security
The application of artificial intelligence to detect, analyze, and respond to cyber threats, and the broader field of understanding how AI-driven attack techniques are reshaping the digital threat landscape. AI cyber security encompasses both defensive AI tools and intelligence about AI-powered adversarial tactics.
AI Cybersecurity
Alternate spelling of AI cyber security. Refers to the intersection of artificial intelligence and cybersecurity, covering AI-enhanced threat detection, AI-driven attack intelligence, and AI-assisted security operations.
AI Threat Intelligence
The collection, analysis, and reporting of information about AI-driven cyber threats, including AI-enhanced attack campaigns, threat actor use of AI tools, and emerging AI-based attack techniques. AI threat intelligence helps organizations anticipate and respond to rapidly evolving cyber risks.
AI Phishing
Phishing attacks that use artificial intelligence to generate highly personalized, convincing fraudulent communications at scale. AI phishing campaigns can reference real names, events, and relationships, dramatically increasing success rates compared to generic phishing.
Deepfake Attack
A cyber attack that uses AI-generated synthetic media — audio, video, or images — to impersonate real individuals. Deepfake attacks are used for executive impersonation, financial fraud, credential theft, and political disinformation.
Voice Cloning Fraud
A form of cyber fraud where attackers use AI to clone a target individual's voice from available recordings, then use the synthetic voice in phone calls to deceive colleagues, customers, or financial institutions into transferring funds or revealing credentials.
AI Ransomware
Ransomware that uses artificial intelligence at various stages of the attack chain, including AI-driven social engineering for initial access, automated network reconnaissance, AI-assisted data exfiltration targeting, and AI-generated victim communications.
Mercenary Spyware
Commercial surveillance software — such as NSO Group's Pegasus, Paragon Graphite, and similar tools — developed by private companies and sold to government clients for mobile device surveillance. Mercenary spyware can compromise smartphones silently, accessing communications, cameras, and microphones.
Zero-Day Vulnerability
A software vulnerability unknown to the software's developers and for which no patch exists. Zero-day vulnerabilities are particularly dangerous because there are no defenses available at time of exploitation. Nation-state actors and well-funded threat groups often hold zero-days for strategic use.
Critical Infrastructure Cyber Security
The protection of essential services and systems — including energy grids, water systems, telecommunications, transportation, healthcare, and financial systems — from cyber threats. Critical infrastructure is a primary target for state-sponsored attacks seeking to cause disruption, economic damage, or public safety incidents.
Executive Cyber Risk
The specific cyber security risks faced by senior executives, board members, and high-profile individuals, including targeted spyware, deepfake impersonation, account takeover, business email compromise, and digital extortion. Executive cyber risk requires personalized, intelligence-led security measures.
Cyber Intelligence Report
A structured analytical document providing intelligence on cyber threats, threat actor activity, attack campaigns, sector-specific risk, and defensive recommendations. Cyber intelligence reports are used by security teams, executives, boards, and risk managers to make informed decisions.
Threat Actor
An individual, group, or organization that conducts malicious cyber activity. Threat actors are categorized by type (nation-state, criminal, hacktivist, insider) and motivation (espionage, financial gain, disruption, ideology). Understanding threat actor profiles is central to cyber intelligence.
SOC Intelligence
Intelligence used by Security Operations Center (SOC) analysts to contextualize security alerts, prioritize investigations, and reduce alert fatigue. AI SOC intelligence uses machine learning to correlate events and surface the most actionable threats.
Incident Intelligence
Post-incident analysis and attribution intelligence that helps organizations understand what happened during a cyber attack, who was responsible, what techniques were used, and how to prevent recurrence. Incident intelligence supports both technical response and strategic risk management.
Digital Risk Monitoring
Continuous monitoring of an organization's digital presence for threats including data leaks, credential exposure, brand impersonation, executive targeting, and dark web mentions. Digital risk monitoring provides early warning of threats before they escalate to incidents.
Explore AI Cyber Security Intelligence
Visit our intelligence hubs for in-depth analysis and reporting on each of these threat areas.
AI Cyber Security Platform