We're forced to take a cybersecurity online course every year, and I'm constantly confused at what the terms are supposed to mean. Like why is spear phishing a thing? Why do we need specialized terms for every conceivable variation of a concept?
Let's just stick with basic terms:
- malware - malicious software
- social engineering - covers calls, texts, emails, etc designed to get access to something they shouldn't
- cracking - breaking cryptography
- security hacking - breaking secure systems by exploiting bugs, such as zero-days or unpatched systems, usually to get privilege escalation
I may be missing a couple, but I think most cybersecurity concepts can fit in one of those categories.