Smart Topics (24 live) - ThreatCluster
Browse 24 live Smart Topics on ThreatCluster, plus 208 archived historic ones. Auto-grouped story arcs across cybersecurity coverage.
Live Smart Topics (24)
- Critical Linux and open-source vulnerabilities enabling RCE and privilege escalation disclosed and patched — Multiple critical vulnerabilities affecting Linux kernels, distributions, and open-source libraries have been disclosed and patched, enabling remote code execution, privilege escalation, and denial of service. (93 clusters · last seen 2026-07-28)
- AI-powered phishing and social engineering campaigns targeting financial services this week — Phishing attacks increasingly leverage AI-generated content, social engineering, impersonation, and novel malware loaders to target financial services, enterprises, and diverse sectors, often leading to sophisticated account takeovers. (40 clusters · last seen 2026-07-28)
- Sophisticated malware and social engineering attacks targeting cryptocurrency ecosystem this week — Cryptocurrency platforms and users face large-scale thefts and frauds through malware, social engineering, smart contract vulnerabilities, blockchain oracle manipulations, and nation-state espionage. (30 clusters · last seen 2026-07-28)
- Ransomware and extortion campaigns disrupt industrial, healthcare, and supply chains with new tactics — Ransomware groups increasingly disrupt manufacturing, healthcare, critical infrastructure, and supply networks using double extortion, software supply-chain vulnerabilities, and unconventional corporate targets. (20 clusters · last seen 2026-07-28)
- Deepfake-enabled social engineering scams and new legal responses — AI deepfake technology is used in video call scams and social engineering frauds, prompting new legal actions, regulatory efforts, and insurance coverage to combat non-consensual AI manipulation. (16 clusters · last seen 2026-07-28)
- Exploitation of token, CI/CD, and authentication flaws in web and cloud platforms — Attackers exploit Insecure Direct Object References, token revocation bypasses, CI/CD automation workflows, and critical authentication vulnerabilities to gain unauthorized access and compromise servers at scale. (12 clusters · last seen 2026-07-28)
- Russian energy sector targeting and threats — Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources. (48 clusters · last seen 2026-05-29)
- Iranian actors targeting energy infrastructure — Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems. (41 clusters · last seen 2026-05-29)
- Chinese government targeting international research institutions — Cyber activities linked to Chinese government entities targeting global research projects and academic institutions. (33 clusters · last seen 2026-05-29)
- Russian government targeting government sectors — Cyber activities by Russian state actors aimed at government entities across various regions and sectors. (32 clusters · last seen 2026-05-29)
- Chinese financial sector targeting and defense activities — Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses. (27 clusters · last seen 2026-05-29)
- North Korean Lazarus Group targeting cryptocurrency platforms — Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure. (21 clusters · last seen 2026-05-29)
- Indian government targeting digital infrastructure — Cyber threat activities by actors targeting India's government digital infrastructure and online services. (18 clusters · last seen 2026-05-29)
- German government targeting cyber threat actors — Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks. (14 clusters · last seen 2026-05-29)
- German financial sector targeted by cyber threat actors — Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns. (13 clusters · last seen 2026-05-29)
- Chinese transportation sector cyber activities — Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities. (12 clusters · last seen 2026-05-29)
- Indian healthcare sector targeted by cyber threat actors — Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns. (11 clusters · last seen 2026-05-29)
- Canadian energy sector targeted by cyber threats — Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities. (11 clusters · last seen 2026-05-29)
- Canadian financial sector targeted by cyber threats — Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure. (11 clusters · last seen 2026-05-29)
- German supply chain actors targeted by malicious packages — Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components. (10 clusters · last seen 2026-05-29)
- Russian DDoS activity targeting infrastructure — Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services. (8 clusters · last seen 2026-05-29)
- TeamPCP supply chain activity — Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools. (8 clusters · last seen 2026-05-29)
- Iranian DDoS activity targeting regional services — This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region. (8 clusters · last seen 2026-05-29)
- Indian financial sector cybersecurity activity — Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts. (6 clusters · last seen 2026-05-29)
Archived Smart Topics (208)
- Active exploitation of critical RCE and privilege escalation vulnerabilities — Multiple clusters report actively exploited critical vulnerabilities that allow remote code execution and privilege escalation across enterprise, Linux, and open-source platforms requiring urgent patching. (72 clusters · last seen 2026-07-27)
- State-linked espionage and influence campaigns targeting governments and critical sectors — Multiple clusters highlight espionage campaigns, surveillance, and hybrid tactics by Russian, North Korean, and other state-linked actors targeting government, defense, political figures, and critical infrastructure. (56 clusters · last seen 2026-07-27)
- Phishing and social engineering campaigns exploiting AI and current events — Phishing operations increasingly leverage AI-generated content, social engineering tied to events, voice phishing, business email compromise, and trusted services to steal credentials and cause financial losses. (37 clusters · last seen 2026-07-27)
- Espionage malware abusing cloud platforms and insider threats — State-linked espionage campaigns use malware exploiting cloud collaboration tools, social media recruitment, insider data theft, and stealthy tactics to target governments and officials. (20 clusters · last seen 2026-07-27)
- Cross-chain cryptocurrency exploits and coordinated attacks — Clusters report large-scale thefts and fraud in the cryptocurrency ecosystem via smart contract vulnerabilities, hot wallet compromises, social engineering, and state-sanctioned crypto abuse. (17 clusters · last seen 2026-07-27)
- Cyberattacks disrupting critical infrastructure and supply chains — Clusters highlight cyber operations causing operational disruptions and sabotage in energy, manufacturing, logistics, nuclear, and space infrastructure sectors amid growing security challenges. (16 clusters · last seen 2026-07-27)
- This Week’s Surge in AI-Driven Offensive Cyber Operations — Threat actors increasingly leverage AI for offensive operations including automated exploit generation, AI-powered phishing, malware delivery, autonomous attacks, and AI-enhanced malware evasion. (60 clusters · last seen 2026-07-26)
- New State-Linked Cyber Espionage Targeting Government and Military — Nation-state actors conduct cyber espionage campaigns using malware, spyware, drones, satellite surveillance, and social media recruitment to infiltrate government, defense, and critical infrastructure networks. (49 clusters · last seen 2026-07-26)
- AI-Enhanced Phishing and Social Engineering Campaigns This Week — Phishing operations exploit social engineering, AI-generated content, brand impersonation, and novel delivery methods to steal credentials and funds from individuals, organizations, and high-value targets across sectors. (46 clusters · last seen 2026-07-26)
- Recent Cryptocurrency Thefts and Blockchain Exploitation Waves — Large-scale crypto thefts, malware targeting wallets and exchanges, bridge vulnerabilities, social engineering, and fraud schemes impact cryptocurrency users and Web3 professionals. (28 clusters · last seen 2026-07-26)
- AI Deepfake and Synthetic Media Abuse in This Week’s Fraud and Misinformation — AI deepfake videos and synthetic media are increasingly used in scams, misinformation campaigns, workplace misconduct, medical image forgery, and extortion, challenging detection and trust. (12 clusters · last seen 2026-07-26)
- Recent Supply Chain Attacks on Developer Ecosystems and Insider Threats — Attacks on software supply chains, including malicious packages and compromised code-signing certificates, combined with insider threats and contractor infiltration by state-aligned hackers, threaten software integrity. (8 clusters · last seen 2026-07-26)
- Russia, North Korea, and others escalate state-sponsored cyber espionage and hybrid warfare this week — Multiple clusters describe nation-state cyber operations by Russian, North Korean, and other actors conducting espionage, malware campaigns, and hybrid warfare tactics against government agencies, critical infrastructure, and military targe (53 clusters · last seen 2026-07-25)
- Phishing campaigns exploiting trusted digital channels surge in credential theft attacks — Phishing and social engineering attacks increasingly abuse trusted platforms, collaboration tools, and recent breach data to steal credentials, session tokens, and financial assets across corporate, government, and consumer targets. (49 clusters · last seen 2026-07-25)
- Crypto and DeFi platforms hit by multi-million dollar cybercrime campaigns — Sophisticated malware, exploits, and fraud campaigns target cryptocurrency wallets, blockchain bridges, DeFi smart contracts, and exchanges, resulting in multi-million dollar thefts and operational disruptions. (28 clusters · last seen 2026-07-25)
- Ransomware and destructive cyberattacks disrupt industrial and critical infrastructure sectors — Ransomware groups and destructive malware campaigns exploit critical vulnerabilities and network infrastructure to disrupt operations, steal data, and demand ransoms in industrial, manufacturing, healthcare, and technology firms. (24 clusters · last seen 2026-07-25)
- Advanced threat actors exploit network edge and legacy infrastructure devices this week — Threat actors actively exploit vulnerabilities and persistence mechanisms in network edge devices such as VPNs, firewalls, routers, and legacy firmware to gain access and conduct espionage or ransomware operations. (16 clusters · last seen 2026-07-25)
- Supply chain attacks leverage package repositories and developer ecosystems this week — Clusters reveal supply chain compromises involving malicious packages and malware campaigns targeting developer tools and repositories such as RubyGems and npm, spreading cryptojacking and other malware. (12 clusters · last seen 2026-07-25)
- Investigations expose concealed state ties in cybersecurity tools and espionage campaigns — Investigations uncover software tools linked to Russian security services and report arrests and espionage campaigns tied to state actors targeting governments and sensitive data worldwide. (8 clusters · last seen 2026-07-25)
- Enterprise credential theft and session token exfiltration campaigns intensify this week — Malware and phishing operations increasingly focus on stealing browser credentials, session tokens, and enterprise data to facilitate unauthorized access and account takeover. (8 clusters · last seen 2026-07-25)
- Critical RCE and privilege escalation vulnerabilities patched across major Linux distros — Multiple critical vulnerabilities enabling remote code execution and privilege escalation have been disclosed and patched across major Linux distributions including Ubuntu, Fedora, Oracle Linux, and openSUSE. (62 clusters · last seen 2026-07-24)
- Russian state-sponsored cyber operations targeting critical infrastructure and hybrid warfare — Russian-linked cyber campaigns employ espionage, infrastructure attacks, deception tactics, and AI tools targeting government, military, and allied nations, including Ukraine and NATO members. (34 clusters · last seen 2026-07-24)
- Active exploitation of critical vulnerabilities in major enterprise software — Critical remote code execution and privilege escalation vulnerabilities in major enterprise software platforms are actively exploited in the wild, prompting urgent patching and incident response. (25 clusters · last seen 2026-07-24)
- Cryptocurrency ecosystem targeted by fraud, theft, and AI-enabled attacks — Cryptocurrency users and platforms face theft, fraud, token scams, and AI-powered malware campaigns targeting wallets, exchanges, and decentralized finance protocols. (21 clusters · last seen 2026-07-24)
- Spike in AI-enabled fraud, deepfake scams, and misinformation campaigns — AI-generated deepfakes and generative media are increasingly used in financial fraud, scams, misinformation campaigns, blackmail, and child exploitation, raising new digital safety challenges. (20 clusters · last seen 2026-07-24)
- Ransomware double extortion campaigns hit critical infrastructure and industrial sectors — Recent ransomware attacks focus on critical infrastructure and industrial organizations, employing double extortion methods that combine data encryption with threats of public data leaks to maximize ransom demands. (17 clusters · last seen 2026-07-24)
- Law enforcement takedowns and sanctions against cybercriminal groups and surveillance facilitators — Authorities have conducted arrests, sanctions, and prosecutions targeting darknet drug syndicates, phishing fraudsters, ransomware facilitators, and surveillance platform operators linked to human rights abuses. (16 clusters · last seen 2026-07-24)
- Supply chain attacks via package typosquatting and code-signing compromise — Attackers exploit software supply chains by injecting malicious code via typosquatting in package repositories and compromising developer tools and code-signing certificates to distribute malware downstream. (12 clusters · last seen 2026-07-24)
- This Week’s AI-Powered Cyber Offense and Defense Campaigns — Clusters cover AI-powered malware campaigns, AI-driven phishing, AI-based vulnerability discovery, autonomous ransomware, and AI-enhanced defense and detection tools used by both attackers and defenders. (68 clusters · last seen 2026-07-23)
- State-Linked Cyber Espionage Targeting Infrastructure and Political Actors — Clusters describe nation-state affiliated threat actors conducting espionage, deceptive malware campaigns, and cyberattacks against governments, military, critical infrastructure, and geopolitical targets. (50 clusters · last seen 2026-07-23)
- Phishing Campaigns Exploiting Trusted Brands and Platforms — Clusters report phishing and social engineering scams impersonating financial and corporate entities, leveraging trusted digital experiences, fake repositories, and evolving techniques to bypass defenses. (27 clusters · last seen 2026-07-23)
- Ransomware Double Extortion and Insider Collusion Campaigns — Clusters highlight ransomware groups using double extortion tactics, insider facilitation, dark web coordination, kernel driver exploits, and social engineering targeting enterprise environments. (24 clusters · last seen 2026-07-23)
- Cryptocurrency Fraud, Theft, and Emerging Quantum Threats — Clusters highlight crypto theft via fraud, bridge exploits, fake apps, regulatory challenges, and emerging quantum risks to wallet and blockchain security. (12 clusters · last seen 2026-07-23)
- Supply Chain Attacks on Open-Source Packages and Developer Environments — Clusters describe malicious compromises of open-source packages, compromised maintainer accounts, and exploitation of software update and proxy mechanisms to infiltrate developer and production environments. (12 clusters · last seen 2026-07-23)
- Russian state-linked cyber espionage and hybrid cyber operations targeting critical infrastructure and government — Multiple clusters detail Russian state-sponsored cyber espionage campaigns and hybrid tactics, including drone-enabled attacks, targeting governments, military logistics, and critical infrastructure. (44 clusters · last seen 2026-07-22)
- AI-enhanced phishing and social engineering campaigns with law enforcement takedowns — Clusters describe widespread phishing, voice phishing, and social engineering attacks enhanced by AI techniques, targeting Microsoft 365, financial services, social media, cloud platforms, and cryptocurrency users, alongside law enforcement (33 clusters · last seen 2026-07-22)
- Ransomware and financially motivated cybercrime disrupting critical infrastructure, industrial, and technology sectors — Clusters highlight ransomware and extortion campaigns targeting critical infrastructure, industrial and tech companies, including insider abuse, third-party breaches, data leaks, and cryptocurrency theft with partial recovery efforts. (24 clusters · last seen 2026-07-22)
- State-linked espionage campaigns abusing collaboration platforms, social media recruitment, and spyware targeting political figures — Clusters describe espionage malware leveraging Microsoft 365 APIs, nation-state recruitment via social media, and spyware campaigns targeting politicians and activists linked to geopolitical tensions. (13 clusters · last seen 2026-07-22)
- Supply chain attacks exploiting developer ecosystems and software signing breaches — Clusters reveal supply chain compromises involving malicious packages, hijacked code-signing certificates, container security issues, and AI-driven supply chain attack vectors threatening software integrity. (12 clusters · last seen 2026-07-22)
- AI-driven attacks exploiting coding assistants and prompt injection — Emerging attacks leverage AI coding assistants, prompt injection techniques, and AI-powered automation to conduct remote code execution, evade detection, and facilitate cybercrime operations. (39 clusters · last seen 2026-07-16)
- Ransomware campaigns leveraging credential theft and insider collaboration — Ransomware groups increasingly collaborate with credential theft specialists and exploit vulnerabilities in third-party software and insider access to conduct extortion and data theft campaigns affecting government, manufacturing, and small (35 clusters · last seen 2026-07-16)
- Russian state-sponsored cyber operations targeting critical infrastructure and allies — Russian FSB and GRU conduct cyberattacks and espionage campaigns against critical infrastructure, military, and government targets across NATO, EU, and Ukraine, accompanied by international diplomatic and legal responses. (25 clusters · last seen 2026-07-16)
- Spike in AI-enabled social engineering and deepfake scams — AI-generated deepfakes, synthetic identities, and AI-enhanced social engineering campaigns increasingly target individuals and enterprises through phishing, vishing, and brand impersonation to steal credentials and commit fraud. (25 clusters · last seen 2026-07-16)
- Cryptocurrency and DeFi platform exploits and laundering schemes — Attackers exploit vulnerabilities in blockchain bridges, DeFi governance, and crypto wallets, while sanctioned nations use cryptocurrency for sanctions evasion and laundering through complex schemes. (24 clusters · last seen 2026-07-16)
- Cyberattacks disrupting critical infrastructure and supply chains — Cyber threats focus on operational disruptions in logistics, industrial partners, renewable energy, telecommunications, and healthcare sectors, impacting public safety and supply chain continuity. (16 clusters · last seen 2026-07-16)
- Supply chain attacks targeting open-source ecosystems and developers — Threat actors, including North Korean groups, expand supply chain compromises involving npm packages, container security, and open-source developer tools to infiltrate software ecosystems and cause data exposure. (12 clusters · last seen 2026-07-16)
- Spike in AI-driven cyberattacks and defenses — Reports highlight the rise of AI-powered cyberattacks including AI-adaptive malware, prompt injection, AI-enabled ransomware, and AI-driven phishing, alongside emerging AI-based security tools and governance efforts. (84 clusters · last seen 2026-07-14)
- Active exploitation of critical RCE and privilege escalation flaws — Multiple clusters report critical software flaws in widely used infrastructure, open-source, AI tools, and enterprise software that enable remote code execution, privilege escalation, and unauthorized control, with active exploitation obser (56 clusters · last seen 2026-07-14)
- Phishing and social engineering surge targeting cloud and crypto users — Threat actors employ sophisticated phishing, vishing, and social engineering techniques exploiting Microsoft 365, Google Workspace, cryptocurrency wallets, hospitality, and professional users to steal credentials and conduct fraud. (40 clusters · last seen 2026-07-14)
- Cryptocurrency attacks, fraud, and sanctions evasion spike — Clusters highlight crypto wallet and Web3 platform vulnerabilities exploited for large-scale thefts, governance attacks, fraud scams, and use of crypto transactions by sanctioned states to bypass restrictions. (28 clusters · last seen 2026-07-14)
- Ransomware evolution with advanced delivery and evasion techniques — Recent ransomware campaigns increasingly leverage AI, signed kernel drivers, modular toolkits, SEO poisoning, proxy malware, and advanced lateral movement methods to enhance stealth, scale, and impact. (24 clusters · last seen 2026-07-14)
- APT campaigns using novel stealth and espionage techniques — APT groups use sophisticated evasion methods including steganography, fileless backdoors, kernel-mode rootkits, and cloud collaboration platforms to conduct espionage targeting military, law enforcement, and critical infrastructure. (24 clusters · last seen 2026-07-14)
- AI deepfake and synthetic media threats targeting politics and journalism — Clusters report AI-driven deepfake videos, synthetic media, and disinformation campaigns targeting political leaders, ethnic groups, and journalists, raising concerns over misinformation and public trust. (16 clusters · last seen 2026-07-14)
- Russian cyber operations targeting critical infrastructure and sanctions — Clusters detail Russian state-sponsored cyber espionage and cyberattacks against EU, NATO, and critical infrastructure sectors, alongside related sanctions enforcement by the US and EU. (10 clusters · last seen 2026-07-14)
- Emerging covert data exfiltration and insider threat techniques — Novel data theft methods such as pixel-based radio emissions from air-gapped systems are emerging alongside rising insider threats involving collusion and negligent insiders causing significant organizational damage. (8 clusters · last seen 2026-07-14)
- Large-scale data breaches exposing sensitive corporate and user information — Multiple incidents involve significant data breaches affecting millions of users and corporate secrets, leading to lawsuits and darknet sales. (4 clusters · last seen 2026-07-10)
- AI-generated disinformation and influence operations — Multiple clusters report AI-driven or foreign-origin online content targeting communities to manipulate social and political narratives. (4 clusters · last seen 2026-07-10)
- Critical vulnerabilities in industrial and operational technology protocols — Several clusters reveal security gaps and critical flaws in industrial protocols and OT environments enabling unauthorized access and control. (4 clusters · last seen 2026-07-10)
- Emerging AI security risks and governance challenges — Clusters highlight new AI-related security threats, governance solutions, and systemic risks from advanced AI models in enterprises and society. (4 clusters · last seen 2026-07-10)
- Critical Linux and open-source vulnerabilities exploited this week — Multiple advisories and active exploitations reveal critical vulnerabilities in Linux kernels, Fedora, SUSE, and widely used open-source libraries that allow privilege escalation, container escapes, and remote code execution requiring urgen (54 clusters · last seen 2026-07-08)