Attacks & Threats
Watering Hole Attack
Also known as: Strategic web compromise
Definition
A targeted attack that compromises a website frequently visited by a specific group of users in order to infect them when they browse it.
Examples
- Attackers compromise an industry trade-association website used by employees of multiple defence contractors.
- Malicious JavaScript on a popular developer forum delivers exploits to visitors from a single targeted company.
Related terms
Drive-by Download
An attack in which malware is silently installed on a victim's device simply by visiting a compromised or malicious website.
Advanced Persistent Threat (APT)
Advanced Persistent Threat (APT) — definition coming soon.
Cross-Site Scripting (XSS)
A web vulnerability that allows attackers to inject malicious scripts into pages viewed by other users, executing in the victim's browser under the site's origin.
Malvertising
The use of online advertising networks to distribute malware, exploits, or scams via legitimate-looking ads served on trusted websites.
Supply Chain Attack
An attack that compromises a trusted third-party software, hardware, or service provider in order to reach its downstream customers.
Phishing
A social-engineering attack in which an attacker impersonates a trusted party to trick a victim into revealing credentials, transferring money, or running malware.