
THREAT‑WATCH
Glossary
Man-in-the-Middle Attack
An attack where the attacker secretly intercepts and potentially alters communication between two parties who believe they're talking directly to each other.
Common scenarios include intercepting traffic on unsecured public Wi-Fi, DNS spoofing to redirect users to a fake site, or compromising a router to intercept all traffic passing through it. Properly implemented encryption (like HTTPS with valid certificates) is the primary defense, since it makes intercepted traffic unreadable even if the attacker successfully positions themselves in the middle.