While chatting with Aaron Higbee of the SecureMe Blog yesterday, he mentioned a cool new site: Threats and Countermeasures . A majority of the contributors are Foundstone consultants and parent company McAfee is paying the bills. Anyone who's been reading my blog for a while knows of my linguistic crusade involving words in the standard risk equation, with risk being a product of threat, vulnerability, and asset value. (See Risk, Threat, and Vulnerability 101 , OCTAVE Properly Distinguishes Between Threats and Vulnerabilities , SANS Confuses Threats with Vulnerabilities , and The Dynamic Duo Discuss Digital Risk .) How does the Threats and Countermeasures site match proper definitions? At left is a screen shot of the site's main knowledge base menu. I don't see the word threat being used correctly here. "Default network appliance passwords" aren't threats; those are vulnerabilities. "Running unnecessary services" is a vulnerability, as is...