Terms of Use
Please read these carefully. By using CyberDilmeth you accept these terms — written in plain English rather than the usual defensive fog.
1.What CyberDilmeth is
CyberDilmeth is an independent cybersecurity education and threat-awareness publication, operated from Colombo, Sri Lanka. We publish explanatory articles, curated summaries of publicly disclosed vulnerabilities, news commentary, and free browser-based security tools.
We are a publisher, not your security provider.
2.Educational purpose — the important disclaimer
Everything on this site is general educational information. It is not professional advice, and reading it does not create any advisory, consulting, or professional relationship between you and us.
Specifically, our content is not:
- Legal advice
- Regulatory or compliance advice
- Financial advice
- A security assessment of your environment
- A substitute for advice from a qualified professional who knows your circumstances
Security guidance that is correct in general can be wrong for your particular systems. Before acting on anything you read here — especially anything involving patching production systems, changing security configuration, or responding to an incident — verify it against your vendor's official documentation and, where the stakes justify it, take qualified professional advice.
We take accuracy seriously. Technical content is reviewed before publication and we correct errors openly. But we cannot guarantee that every statement is complete, current, or applicable to you, and you use the information at your own risk.
3.Threat intelligence — what it is and is not
Our Threat Intelligence section is compiled and summarised from public sources, principally:
- the CISA Known Exploited Vulnerabilities (KEV) catalog
- the National Vulnerability Database (NVD)
- Exploit Prediction Scoring System (EPSS) data published by FIRST.org
- vendor security advisories
We are transparent about this. We do not claim first-party telemetry, original vulnerability research, or independent verification of exploitation. Where we summarise another organisation's advisory, we attribute it and link to the original.
Please understand the following:
- Our summaries are not authoritative. The vendor advisory and the primary source always take precedence. Patch according to the vendor's instructions, not ours.
- Remediation dates shown on advisory pages generally originate from CISA and apply to United States federal civilian agencies. They are shown as useful context and as a prioritisation signal. They are not a deadline that applies to you, and you should not treat them as one.
- Absence is not safety. A vulnerability not appearing on this site does not mean it does not exist or does not affect you. Our coverage is selective, not exhaustive.
- Severity scores and exploit probabilities are estimates produced by third parties using published methodologies. They inform prioritisation; they do not determine your actual risk, which depends on your environment.
- Data may lag. Feeds refresh periodically. Time-critical decisions should be based on the primary source.
4.Using our tools
We provide free, browser-based security tools. You may use them for personal and business purposes at no cost.
4.1 What you must not do with them
You may not use any tool on this site to:
- Test, probe, scan or analyse credentials or systems you do not own or have documented authorisation to test
- Attempt to attack, overload, disrupt, or gain unauthorised access to any system, whether ours or a third party's
- Circumvent rate limits, run automated or scripted requests at volume, or use the site as infrastructure for any automated process
- Do anything unlawful in your jurisdiction
Authorised security testing of systems you are permitted to test is entirely legitimate and welcome. Using our tools against someone else's systems without permission is not, and may be a criminal offence where you are.
4.2 No guarantee of results
Our tools are provided for education and self-assessment.
A password our analyzer rates as strong is not guaranteed to be secure. A password our breach check does not find is not guaranteed to be unbreached — it means it does not appear in the specific public corpus queried. A policy check that passes does not mean your organisation is compliant with anything.
These are indicators to learn from, not certifications to rely on.
4.3 Privacy of tool input
How our tools handle what you type is set out in our Privacy Policy, section 6. In short: the password generator, analyzer and policy checker run entirely in your browser; the breach check uses k-anonymity so that your password never leaves your device.
You remain responsible for what you paste into any web page, here or anywhere else. We recommend never entering live production credentials or secrets into any online tool, including ours.
5.Acceptable use of the site
You agree not to:
- Use the site for any unlawful purpose
- Attempt to gain unauthorised access to any part of the site, its server, or connected infrastructure
- Introduce malware, or attempt to interfere with the site's operation or availability
- Scrape, harvest, mirror or systematically download content at scale, or use automated means to extract our threat intelligence data in bulk
- Frame or misrepresent our content as your own
- Impersonate CyberDilmeth, a contributor, or a technical reviewer
- Republish our content in a way that suggests we endorse a product, vendor or position that we do not
Reasonable, attributed quotation and linking is welcome and encouraged. We want our work to be shared. What we object to is wholesale republication and misattribution.
6.Intellectual property
6.1 Our content
Original content on this site — articles, analysis, commentary, tool code, design, and the CyberDilmeth name and logo — is owned by us or our contributors and is protected by copyright and trade mark law.
You may:
- Read, print, and share content for personal or internal organisational use
- Quote reasonable extracts with clear attribution and a link to the original page
You may not, without written permission:
- Republish articles in full
- Use our content commercially, including in paid training material or client deliverables
- Use the CyberDilmeth name or logo in a way that implies endorsement or partnership
Where a page or downloadable resource carries its own licence, that licence governs it.
6.2 Third-party material
Some content on this site derives from or reproduces public-sector and third-party sources:
- CISA KEV catalog and NVD — works of the United States Government, generally not subject to copyright in the US. We attribute them regardless.
- EPSS — published by FIRST.org and used in accordance with their terms.
- Vendor advisories, CVE identifiers, and MITRE ATT&CK references — remain the property of their respective owners.
All product names, trade marks and company names mentioned belong to their respective owners. Their appearance on this site does not imply any affiliation, endorsement, partnership, or sponsorship in either direction. We are vendor-neutral and we accept no payment for editorial coverage. Advertising and sponsorship are governed by section 7.
6.3 Your submissions
If you send us an article, correction, or other material, you confirm it is your own work and you grant us a non-exclusive, worldwide licence to publish, edit and archive it in connection with the site. You keep ownership of your work.
We reserve full editorial rights, including the right to edit, decline, or withdraw any submission.
7.Advertising and editorial independence
This site carries advertising. Advertising helps keep the guidance here free to read, and we would rather state that openly than let you discover it from a script blocker.
The rules we hold ourselves to are these:
- Advertising buys space, never coverage. Advertisers have no influence over what we publish, no advance sight of articles or advisories, and no ability to have anything removed.
- No pay-for-placement in threat intelligence. Nothing in our advisories, severity assessments or recommendations can be bought.
- Sponsored content is always labelled as sponsored, clearly and on the page itself — not in a footnote.
- Ads are not endorsements. An advertisement appearing beside an article says nothing about our view of that product or vendor, and we do not vet advertisers' claims.
- No advertising on our tool pages. The password tools handle sensitive input, so no third-party advertising or analytics script is loaded on them.
Advertising cookies are set only if you consent to them. How that works, and how to withdraw consent, is set out in our Cookie Notice.
If you ever believe our coverage has been influenced by an advertiser, tell us at [email protected]. We would treat that as a serious complaint.
8.What we do not publish
We write for defenders. We do not publish working exploit code, weaponised proof-of-concept material, malware source, offensive tooling, or step-by-step attack instructions that provide meaningful new offensive capability.
If you are looking for those things, this is not that kind of site, and requests for them will be declined.
9.Links to other sites
We link extensively to primary sources. Those sites are outside our control. A link is not an endorsement of the linked site's content, products, accuracy, or security practices, and we accept no responsibility for them.
10.Availability
We aim to keep the site available and current, but we do not guarantee uninterrupted access. We may suspend, withdraw, or change any part of the site — including any tool — at any time and without notice.
We are not liable to you if the site is unavailable for any period.
11.No warranties
The site and everything on it is provided "as is" and "as available", without warranties of any kind, express or implied, including any implied warranties of merchantability, fitness for a particular purpose, accuracy, or non-infringement.
We do not warrant that the content is accurate, complete, current, or free of error, or that the site is free of malicious code.
12.Limitation of liability
To the fullest extent permitted by law, we are not liable for any loss or damage arising from your use of, or inability to use, this site or its content — including any indirect, incidental, consequential or special loss, loss of profit, loss of data, business interruption, or any security incident.
If you act on information from this site and something goes wrong, that is your risk. Verify before you act, especially in production.
Nothing in these terms excludes or limits liability that cannot lawfully be excluded or limited.
13.Indemnity
You agree to indemnify us against any claim, loss, or expense arising from your breach of these terms or your misuse of the site or its tools — in particular, from any use of our tools against systems you were not authorised to test.
14.Security research and responsible disclosure
We welcome good-faith security research into this website.
If you find a vulnerability, report it to [email protected] and give us reasonable time to fix it before disclosing publicly.
We will not pursue legal action against researchers who act in good faith, avoid privacy violations, avoid degrading our service or that of our users, do not access, modify or destroy data beyond what is necessary to demonstrate the issue, and give us a reasonable opportunity to respond.
If we have got something wrong, we would rather hear it from you than read about it somewhere else. Full details are in our Responsible Disclosure policy.
15.Corrections
If you believe something on this site is wrong, tell us at [email protected].
We correct material errors openly and note what changed and when. We do not silently delete published content; superseded material is archived with a pointer to what replaced it. Getting things right matters more to us than looking as though we never got them wrong.
16.Privacy
Your use of this site is also governed by our Privacy Policy and Cookie Notice, which form part of these terms.
17.Changes to these terms
We may update these terms. The version number and date above always reflect the current version, and continued use of the site after a change means you accept the updated terms.
Material changes will be flagged on the site rather than made quietly.
18.Governing law
These terms are governed by the laws of Sri Lanka, and the courts of Sri Lanka have exclusive jurisdiction over any dispute arising from them.
If you are a consumer resident elsewhere, this does not deprive you of any mandatory protections available to you under the law of your own country.
19.General
If any provision of these terms is found unenforceable, the rest remain in force. Our failure to enforce a provision is not a waiver of it. These terms, together with the Privacy Policy and Cookie Notice, are the entire agreement between us regarding your use of the site.
20.Contact
| Purpose | Address |
|---|---|
| General enquiries | [email protected] |
| Editorial corrections | [email protected] |
| Security vulnerability reports | [email protected] |
| Privacy and data requests | [email protected] |
| Contributing to CyberDilmeth | [email protected] |
| Permission and licensing requests | [email protected] |
CyberDilmeth — Terms of Use v1.0, 24 July 2026.
See also: Privacy Policy · Cookie Notice · Responsible Disclosure