Account Security
Controls and habits that keep login credentials, sessions, and account recovery options from being abused.
Read full definitionShouldEye Trust Intelligence Glossary
Online-safety definitions for malware, authentication, malicious links, domain risk, and safe browsing.
Educational information only. ShouldEye does not provide legal, banking, or individualized financial advice. Dispute rights, deadlines, and outcomes depend on your payment method, card network, issuer, processor, jurisdiction, and the facts of your case. Legal Disclaimers
65 published definitions in this topic.
Controls and habits that keep login credentials, sessions, and account recovery options from being abused.
Read full definitionSoftware that delivers unwanted advertising and may also track browsing or degrade device performance.
Read full definitionAn API key leak is accidental publication of a secret token that can unlock paid services, private data, or admin actions.
Read full definitionAttachment sandboxing opens files in an isolated environment to reduce malware detonation risk.
Read full definitionAttack surface is the set of exposed interfaces—apps, APIs, emails, and people—where an attacker can try to get in.
Read full definitionA CAA DNS record restricts which certificate authorities may issue TLS certificates for a domain.
Read full definitionCertificate pinning restricts which TLS certificates an app will trust for a given host to reduce some MITM risks.
Read full definitionA compromised account is one an attacker can access because credentials, cookies, reset links, or MFA were stolen or guessed.
Read full definitionContent Security Policy is a browser header that restricts which scripts and resources a page may load to reduce XSS impact.
Read full definitionA credential stuffing attack automates login attempts using breached username/password pairs against other sites.
Read full definitionCredential stuffing defense includes unique passwords, MFA, breach monitoring, and login anomaly detection.
Read full definitionData exfiltration is unauthorized transfer of sensitive data out of a system—often the goal of ransomware and insider attacks.
Read full definitionDefense in depth stacks multiple security controls so one failure does not fully expose users or systems.
Read full definitionDevice attestation cryptographically checks whether a client device is genuine and in an expected state.
Read full definitionDNS hijacking redirects domain lookups to attacker-controlled destinations so victims land on malicious sites.
Read full definitionDNS over HTTPS encrypts DNS lookups so network observers cannot easily see which domains you resolve.
Read full definitionMalware installation triggered merely by visiting a compromised page, often without a clicked installer.
Read full definitionEndpoint detection monitors devices for malware and suspicious behavior after preventive controls fail.
Read full definitionA hardware security key is a physical authenticator used for phishing-resistant sign-in.
Read full definitionA homograph domain uses lookalike Unicode characters so a fake domain appears identical to a trusted brand.
Read full definitionIncident response is the organized process of detecting, containing, and recovering from security events.
Read full definitionAn info stealer is malware designed to harvest passwords, cookies, crypto wallets, and autofill data from a victim’s device.
Read full definitionLateral movement is an attacker’s progression from one compromised account or system to others inside a network.
Read full definitionLeast privilege grants only the minimum access needed for a task, limiting blast radius after compromise.
Read full definitionA Malicious Link is a URL that leads to phishing, malware, scams, or other harmful destinations disguised as something legitimate.
Read full definitionA malware distribution site delivers malicious downloads via fake updates, cracks, ads, or compromised pages.
Read full definitionA man-in-the-middle attack intercepts communications between two parties to steal or alter data.
Read full definitionAn attack that intercepts communications between two parties to steal or alter data in transit.
Read full definitionAn MFA fatigue attack spams push approvals until a tired user accepts, granting the attacker access.
Read full definitionMixed content is insecure HTTP resources loaded inside an HTTPS page, weakening encryption and enabling injection.
Read full definitionPractices and protections that reduce harm from scams, malware, harassment, and other digital risks.
Read full definitionPasskey phishing resistance comes from cryptographic origin binding that blocks classic “type your password on a fake site” attacks.
Read full definitionA password manager stores unique credentials securely so people avoid reuse across sites.
Read full definitionPassword reuse risk is the chance that one breached site unlocks many others because the same password was reused.
Read full definitionA password spray attack tries a few common passwords across many accounts to avoid lockouts while finding weak credentials.
Read full definitionTrying a few common passwords against many accounts to avoid lockouts while finding weak credentials.
Read full definitionPatch lag is the delay between a fix becoming available and systems actually applying it.
Read full definitionPrivilege escalation is gaining higher access rights than originally granted after an initial compromise.
Read full definitionRate limiting caps how often an action can be attempted, slowing brute-force, stuffing, and abuse.
Read full definitionBrowser and threat-intelligence protections that warn users about known phishing, malware, and deceptive sites.
Read full definitionA Safe Browsing match means a URL or resource was flagged by a malware/phishing protection list used by browsers.
Read full definitionSafe link scanning checks URLs against threat intelligence before a user opens them.
Read full definitionSecret scanning automatically searches code and logs for leaked keys, tokens, and credentials before attackers find them.
Read full definitionSecure by default means products ship with strong security settings enabled without requiring expert configuration.
Read full definitionA secure enclave is isolated hardware that protects keys and sensitive operations from the main operating system.
Read full definitionSecurity awareness training teaches people to recognize phishing, social engineering, and unsafe practices.
Read full definitionAn incident where unauthorized parties access, exfiltrate, or disrupt systems or sensitive data.
Read full definitionA security header is an HTTP response directive that hardens browsers against clickjacking, XSS, and mixed-content risks.
Read full definitionSecurity posture is the overall strength of an organization’s defenses, configurations, and response readiness.
Read full definitionsecurity.txt is a standard file that tells researchers how to report vulnerabilities to a site’s security team.
Read full definitionSession cookie theft steals authenticated browser cookies so attackers can hijack accounts without knowing the password.
Read full definitionA session replay attack reuses stolen cookies or tokens to act as a logged-in user without the password.
Read full definitionCompromising upstream packages, build systems, or updates to infect downstream users at scale.
Read full definitionSoftware that secretly monitors activity or steals information from a device without informed consent.
Read full definitionAn SSL/TLS certificate enables HTTPS encryption for a website and helps browsers verify the site’s cryptographic identity.
Read full definitionA supply chain compromise inserts malicious code into trusted dependencies, build systems, or update channels.
Read full definitionA link that shows warning signs such as typosquatting, unexpected domains, or known malicious patterns.
Read full definitionA threat model identifies what you protect, who might attack it, and which controls matter most for those risks.
Read full definitionA typosquat domain is a lookalike URL registered to catch mistyped traffic for phishing or brand abuse.
Read full definitionA tool that analyzes a link’s destination, reputation, and payload risk before a user clicks through.
Read full definition