Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
26 topics
State-linked cyber espionage and hybrid warfare targeting critical sectors
Oct 1, 2026Clusters describe sophisticated state-sponsored cyber espionage, hybrid warfare activities, and cyberattacks targeting government, defense sectors, critical infrastructure, and geopolitical adversaries amid ongoing conflicts.
Active exploitation of critical RCE vulnerabilities across major software
Oct 1, 2026Multiple clusters report ongoing active exploitation of critical remote code execution (RCE) vulnerabilities across diverse widely used software platforms, including enterprise, infrastructure, and security tools, enabling attackers to execute arbitrary code remotely and escalate privileges.
Surge in AI-enabled social engineering, phishing, and deepfake scams
Oct 1, 2026Clusters highlight the growing use of AI-driven phishing, social engineering, and deepfake impersonations to defraud individuals and organizations, including financial institutions and crypto users, with emerging countermeasures.
Critical auth bypass vulnerabilities disclosed in open-source and industrial software
Oct 1, 2026Several critical authentication and authorization bypass flaws have been disclosed in open-source libraries, industrial control, and IoT devices, enabling unauthorized access, credential theft, and privilege escalation.
Cryptocurrency platform exploits and laundering via privacy coins
Oct 1, 2026Multiple incidents involve cryptocurrency exchange hacks, smart contract exploits, wallet thefts on various platforms including Apple devices, and laundering of stolen funds using privacy-focused coins.
Ransomware campaigns with combined encryption and data leak extortion
Oct 1, 2026Multiple ransomware groups continue to target organizations across industries and countries, combining encryption attacks with public data leak extortion tactics causing operational disruptions and financial losses.
Phishing and social engineering campaigns exploiting novel vectors and trusted platforms
Oct 1, 2026Threat actors increasingly use innovative phishing techniques leveraging holidays, homoglyph attacks, OAuth flows, QR codes, calendar invites, and trusted communication platforms to harvest credentials and deploy malware.
Security incidents from autonomous AI agents and prompt injection attacks
Oct 1, 2026Multiple incidents and clusters report security challenges from autonomous AI agents causing unauthorized data access, prompt injection attacks, and breaches of sensitive government, health, and enterprise systems.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
621 topicsNo longer detected as trending. Sorted newest archived first.
This Week’s Surge in AI-Enhanced Cyber Attacks and Automation
Sep 30, 2026Clusters highlight the growing use of AI technologies including autonomous agents, prompt injection, AI-powered phishing, deepfake scams, and AI-assisted vulnerability discovery, which are accelerating attack speed, scale, and evasion while complicating defense efforts.
Critical Linux Kernel and Virtualization Vulnerabilities Under Active Exploitation
Sep 30, 2026Multiple clusters report critical and zero-day vulnerabilities in Linux distributions such as Fedora, SUSE, and Ubuntu, including kernel flaws, firewall bugs, and virtualization components, with active exploitation impacting system security and requiring urgent patching.
Active Exploitation of Critical RCE and Privilege Escalation Vulnerabilities
Sep 30, 2026Multiple clusters report ongoing active exploitation of critical remote code execution (RCE) and privilege escalation vulnerabilities across widely used enterprise platforms, open-source projects, and infrastructure software, enabling attackers to gain unauthorized access and control.
AI-Driven Phishing and Deepfake Social Engineering Campaigns
Sep 30, 2026Phishing operations have evolved to use AI-generated content, deepfake audio/video, homoglyph domain spoofing, and social engineering targeting authentication mechanisms and customer support channels to steal credentials and bypass defenses.
Multi-Sector Ransomware Campaigns with Data Theft and Disruption
Sep 30, 2026Multiple ransomware groups have launched coordinated campaigns targeting a wide range of industries including healthcare, government, manufacturing, legal, and critical infrastructure, combining data encryption, exfiltration, leak sites, and destructive tactics.
Active exploitation of critical RCE and privilege escalation in Linux and enterprise software
Sep 29, 2026Multiple clusters report active exploitation of critical remote code execution and privilege escalation vulnerabilities across widely used enterprise software, Linux distributions (including SUSE, Fedora, Ubuntu), kernels, and open-source components, prompting urgent patches and alerts.
Ransomware campaigns with evolving tactics and data leak extortion
Sep 29, 2026Multiple ransomware groups have targeted organizations across healthcare, finance, government, legal, professional, education, and infrastructure sectors worldwide using novel tactics such as Active Directory exploitation, VPN and credential abuse, public victim shaming, and advanced evasion techniques, frequently causing operational disruption and data leaks.
AI-driven cyberattacks leveraging autonomous agents and deepfakes
Sep 29, 2026Clusters highlight AI-powered threats including autonomous attack agents, AI-generated deepfakes used in scams, phishing, social engineering, identity fraud, and AI-enhanced malware targeting government, healthcare, critical infrastructure, and enterprise systems, raising new challenges in detection, governance, and accountability.
Cryptocurrency ecosystem attacks with AI-enabled deception and North Korean thefts
Sep 29, 2026Clusters describe large-scale cryptocurrency platform breaches, smart contract flaws, wallet thefts linked to North Korean actors, malware targeting blockchain ecosystems, and AI-driven scams leveraging fake agents and deepfakes to deceive users and influencers.
AI-driven cyber threats leveraging automation and autonomous malware
Sep 28, 2026AI-powered attacks are rapidly evolving, employing automation, agent impersonation, AI-generated phishing, autonomous malware, and deepfake scams to escalate breaches, evade detection, and conduct sophisticated social engineering.
Active exploitation of critical vulnerabilities in web platforms and WordPress
Sep 29, 2026Multiple clusters report rapid weaponization and active exploitation of critical vulnerabilities in popular web platforms, CMS software, and WordPress plugins, enabling remote code execution, unauthorized access, and widespread site compromises.
This Week’s Cryptocurrency Exchange Hacks and State-Linked Scams
Sep 30, 2026Large-scale cryptocurrency exchange breaches, wallet compromises, and social engineering scams have surged, with some attacks attributed to North Korean state-sponsored groups and involving illicit fund laundering.
State-linked cyber espionage targets political and activist communities
Sep 28, 2026State-aligned actors conduct espionage and surveillance operations using malware, compromised devices, and social engineering to target government entities, political critics, activists, and sensitive industries, with arrests and convictions reported.
Ransomware campaigns escalate with data theft and automation across sectors
Sep 28, 2026Multiple ransomware groups have launched widespread campaigns across healthcare, government, finance, infrastructure, and other sectors, increasingly combining data exfiltration, leak sites, automation, and identity exploitation to maximize impact and pressure victims.
Critical Web Platform and CMS Vulnerabilities Under Active Exploitation
Sep 30, 2026Rapidly exploited critical vulnerabilities in popular web platforms and content management systems such as WordPress, Roundcube, and Grav CMS enable remote code execution and unauthorized access.
Active exploitation of critical RCE and privilege escalation vulnerabilities in major software
Sep 25, 2026Numerous critical vulnerabilities enabling remote code execution, privilege escalation, authentication bypass, and injection attacks have been disclosed and actively exploited in popular enterprise, open-source, and network software requiring urgent patching.
Ransomware campaigns with data leaks and extortion hitting multiple sectors
Sep 25, 2026Multiple ransomware groups have launched attacks across various industries worldwide, leveraging automation, data exfiltration, and leak sites to pressure victims for ransom payments.
Recent data breaches exposing sensitive personal and organizational data
Sep 25, 2026Recent data breaches have compromised large volumes of sensitive personal, financial, and corporate data across healthcare, government, financial services, and other industries.
Phishing and social engineering exploiting AI, holidays, and brand impersonation
Sep 29, 2026Multiple clusters describe sophisticated phishing and social engineering attacks leveraging AI-generated content, holiday-themed lures, homoglyphs, brand impersonation, and credential theft to compromise financial institutions, cloud services, and enterprise accounts.
Deepfake and AI-enabled identity fraud hits political and financial sectors
Sep 28, 2026AI-generated deepfakes and synthetic media are increasingly used for political disinformation, election interference, identity fraud, and scams targeting individuals and financial institutions, prompting new detection and policy responses.
Surge in AI-Driven Cyber Threats: Deepfakes, Phishing, and Autonomous Attacks
Sep 24, 2026AI technologies are increasingly leveraged for malicious purposes such as deepfake-enabled social engineering, AI-powered phishing campaigns targeting education and telecom, autonomous malware, and AI-enhanced offensive cyber operations impacting finance, politics, and industrial systems.
Novel Phishing and Social Engineering Campaigns Targeting Credentials and Crypto
Sep 24, 2026Attackers employ innovative phishing methods including holiday-themed lures, homoglyph attacks, voice phishing, AI-enhanced scams, QR code fraud, OAuth exploits, and impersonation to steal credentials and cryptocurrency from individuals and enterprises.
Espionage and State-Sponsored Cyber Operations with Insider Threats Amid Geopolitical Tensions
Sep 24, 2026Nation-state actors engage in cyber espionage campaigns using insider access, covert surveillance, recruitment, and geopolitical cyber conflict, targeting military, political, and sensitive technology sectors including AI and semiconductor theft.
Emerging Malware Campaigns Exploiting Software Supply Chains and Open-Source Ecosystems
Sep 24, 2026New malware strains leverage compromised package repository accounts, malicious npm packages, Go modules, Terraform providers, and OSINT tools to infiltrate systems and steal credentials.