Here are a few security terms we use throughout this material:
Attacker (or adversary): Someone who attacks a system without authorization to try to make a system violate its security requirements, e.g., to steal or change data, or to take control of the system.
Vulnerability: A defect that an attacker can exploit to violate some security requirement.
Finding: A report that something might be a vulnerability. A finding isn’t a confirmed vulnerability until it’s validated.
Exploit: To use a vulnerability to violate a security requirement; also, the input or program that does so.
Proof of concept (PoC) / proof of vulnerability (PoV): A concrete, reproducible demonstration that a vulnerability exists. Its core is a specific input (plus any configuration it needs) that makes the system fail its security requirements. It’s often packaged as “a script, a crashing input, or a failing test” [Yan2026], usually with a way to check the result. A PoC doesn’t need to be a complete, weaponized exploit. The term PoV is common in work related to DARPA’s AIxCC [Zhang2026], though some sources use that term for somewhat different ideas.
Chaining: Combining multiple defects, each of which may seem harmless, into a working attack.