A third-party cookie is a cookie set by a domain other than the website the visitor is currently viewing, typically placed by an embedded resource like an ad network, allowing that outside domain to recognize the same visitor across multiple unrelated websites.
This cross-site recognition is what makes third-party cookies valuable for ad targeting — an ad network can see that the same browser visited a shoe website last week and is now reading a news article, and serve a shoe ad accordingly. It's also what's made them the primary target of privacy crackdowns: major browsers restrict them by default, and regulations like GDPR generally require explicit consent before they can be set, unlike first-party cookies set directly by the site being visited.
When a news website embeds a display ad served by an ad network, that network can set a cookie under its own domain, not the news site's — letting it recognize the same visitor later on a completely different website using the same ad network.
Because they enable tracking a person across unrelated websites without a direct relationship between the person and the tracking domain, which browser makers and regulators have increasingly treated as a privacy risk requiring restriction or consent.
A first-party cookie is set by the website the visitor is directly interacting with, like a shopping cart cookie; a third-party cookie is set by a different domain embedded within that page, such as an ad or tracking script.
No — many analytics platforms use first-party cookies, or avoid cookies entirely with cookieless methods, since cross-site tracking isn't necessary just to measure a single site's own traffic.