Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
27 topics
Active exploitation of critical RCE and privilege escalation zero-days in enterprise and open-source software
Oct 2, 2026Multiple clusters report urgent and active exploitation of critical remote code execution and privilege escalation vulnerabilities across widely used enterprise software, Linux distributions, and open-source libraries, including zero-days and rapid weaponization.
Drone and counter-drone operations in ongoing geopolitical conflicts
Oct 2, 2026Reports cover drone attacks on critical infrastructure, military drone deployments, counter-drone technologies, and related investments amid ongoing regional and maritime conflicts.
AI autonomous agents driving breaches and governance challenges
Oct 2, 2026Clusters describe AI-powered autonomous agents breaching government and healthcare systems, AI-driven cyberattacks, AI-enhanced phishing and scams, and the resulting regulatory and governance challenges.
State-linked espionage and cyber operations targeting governments and critical infrastructure
Oct 2, 2026Multiple clusters highlight espionage campaigns, state-sponsored cyberattacks, surveillance activities, arrests, and law enforcement responses targeting governments, academia, critical infrastructure, and journalists.
Critical zero-day exploits in enterprise network and security products
Oct 2, 2026Multiple clusters report zero-day and critical vulnerabilities in enterprise network devices, security products, and virtualization software being actively exploited to gain unauthorized access and disrupt defenses.
Geopolitical tensions fueling cyber, kinetic, and hybrid warfare including disinformation
Oct 2, 2026Clusters reveal cyberattacks, drone strikes, disinformation campaigns, sanctions, and military escalations linked to conflicts involving Russia, Ukraine, Iran, China, and other actors.
Ransomware and malware campaigns disrupting critical infrastructure and healthcare
Oct 2, 2026Ongoing ransomware and malware campaigns target critical infrastructure, healthcare, government, legal, transportation, and other sectors, often combining extortion, data leaks, and destructive tactics.
AI-enhanced phishing, social engineering, and BEC campaigns
Oct 2, 2026Multiple clusters describe phishing and social engineering attacks targeting healthcare, education, military, and AI sectors using AI-driven deepfakes, QR codes, OAuth flows, and impersonation scams.
Cryptocurrency theft and laundering exploiting privacy protocols and smart contracts
Oct 2, 2026Clusters report large-scale cryptocurrency thefts, laundering through privacy-enhanced protocols, smart contract exploits, and related social engineering scams targeting crypto platforms and wallets.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
629 topicsNo longer detected as trending. Sorted newest archived first.
Critical WordPress plugin vulnerabilities enabling unauthorized access and code execution
Sep 5, 2026Multiple WordPress plugin flaws allow attackers to access sensitive files, modify content, or execute code without authorization, posing significant risks to websites.
Active exploitation of critical RCE and privilege escalation vulnerabilities
Aug 24, 2026Clusters covering severe vulnerabilities in widely used software, open-source infrastructure, Linux distributions, and enterprise platforms that enable remote code execution, privilege escalation, and account takeover, with active exploitation observed.
State-linked cyber espionage targeting critical infrastructure and national security
Aug 24, 2026Clusters detailing cyberattacks, espionage, and influence operations by nation-state actors including Chinese and Russian groups targeting government, industrial, satellite, and critical infrastructure sectors.
Cryptocurrency and DeFi exploits, fraud, and emerging physical attacks
Aug 27, 2026Exploits in blockchain governance, wallet apps, and phishing campaigns cause significant financial losses, while physical coercion and social attacks increasingly target cryptocurrency holders.
Cryptocurrency exploits, wallet thefts, and social engineering fraud
Aug 24, 2026Clusters reporting exploits and thefts targeting cryptocurrency wallets, DeFi governance, exchanges, and users through vulnerabilities, phishing, wrench attacks, and malicious tooling.
Cryptocurrency ecosystem exploits, governance attacks, and phishing incidents
Aug 29, 2026Multiple incidents involve attacks on cryptocurrency platforms exploiting governance flaws, blockchain vulnerabilities, phishing campaigns, and data breaches targeting wallets, DeFi apps, and token theft.
Physical and electronic attacks on critical infrastructure: drone strikes and GPS jamming
Aug 29, 2026Recent incidents include drone attacks on logistics and industrial sites and GPS jamming disrupting aviation and critical infrastructure operations, raising concerns over physical and electronic security.
Cryptocurrency ecosystem attacks: phishing, governance exploits, wallet thefts, and domain hijacking
Aug 28, 2026Clusters describe phishing scams impersonating tax authorities, DeFi governance attacks, hardware wallet vulnerabilities, domain hijacking, and large-scale crypto thefts impacting users and exchanges.
Cryptocurrency and DeFi Exploits, Scams, and Malware Campaigns
Aug 25, 2026Multiple incidents involve exploitation of DeFi governance, blockchain platforms, and cryptocurrency users through malware, social engineering, impersonation scams, and fraudulent extensions.
Malware Campaigns Targeting Financial Apps and macOS Users
Aug 25, 2026Reports highlight expansion of Android banking malware and MacSync stealer campaigns using advanced evasion and malvertising to steal credentials from financial and macOS users.
Phishing and social engineering targeting cryptocurrency and financial services
Aug 23, 2026Phishing and social engineering attacks increasingly target cryptocurrency users, wallets, and financial institutions using advanced impersonation, novel vectors, and evasion techniques to steal credentials and funds.
Critical RCE and Privilege Escalation Vulnerabilities Actively Exploited This Week
Aug 25, 2026Multiple clusters report critical remote code execution and privilege escalation vulnerabilities in widely used software, plugins, and developer tools that are actively exploited or require urgent patching.
Active exploitation of critical RCE and privilege escalation vulnerabilities
Aug 23, 2026Multiple reports detail critical remote code execution and privilege escalation vulnerabilities across enterprise software, Linux/open-source platforms, and widely used plugins that are actively exploited by attackers.
Malware campaigns leveraging novel loaders and cloud platforms for C2
Aug 24, 2026Clusters describing malware distribution using advanced loaders and exploiting cloud and collaboration platforms like Microsoft 365, GitHub, and Electron apps for command-and-control and persistence.
GPS jamming disrupts aviation and critical infrastructure
Sep 2, 2026Authorities detected and mitigated GPS jamming devices causing disruptions to aviation and critical infrastructure systems, highlighting emerging physical-layer cyber threats.
AI-Driven Cybercrime: Malware Evolution and Offensive Automation This Week
Aug 25, 2026Threat actors increasingly leverage AI-generated malware, prompt injection, autonomous agents, and AI-powered offensive tools to enhance cybercrime campaigns, social engineering, and exploit development.
Supply chain compromises and malware via software ecosystems and brand impersonation
Aug 28, 2026Attackers infiltrate software supply chains including Rust crates and browser extensions, and use brand impersonation with AI and emoji obfuscation to distribute malware and steal credentials.
Spike in AI-driven cybercrime and offensive AI attacks
Aug 22, 2026Threat actors increasingly employ AI-generated exploits, offensive AI tools, prompt injection attacks, and autonomous AI agents to conduct cyberattacks, fraud, and identity manipulation across industrial and enterprise systems.
Malware campaigns using novel delivery, evasion, and social engineering techniques
Aug 27, 2026Recent malware operations employ advanced loaders, emoji obfuscation, SVG phishing, expired domains, blockchain-based botnet command storage, and social engineering on collaboration platforms to evade detection and steal credentials.
Malware campaigns leveraging novel delivery and evasion techniques
Aug 23, 2026Threat actors employ advanced loaders, emoji obfuscation, malicious browser extensions, AI brand impersonation, compromised hardware drivers, and malvertising to distribute malware and infostealers.
AI-enhanced phishing and social engineering campaigns with novel tactics
Aug 24, 2026Clusters describing sophisticated phishing, vishing, social engineering, and impersonation attacks using AI deepfakes, novel vectors like SVG files, brand impersonation, and law enforcement takedowns of phishing infrastructure.
AI-Generated Deepfakes and Synthetic Identity Abuse in Fraud and Misinformation
Aug 25, 2026Clusters cover the use of AI deepfakes and synthetic identities in political misinformation, financial scams, harassment, and legal disputes, alongside emerging defenses.
AI-enabled cyber threats: deepfakes, automation, and offensive tools
Aug 24, 2026Clusters highlighting AI-driven attacks including deepfake impersonation scams, AI-automated exploitation, prompt injection in AI tools, autonomous malware evolution, and AI-enhanced social engineering.
Surge in AI-driven cybercrime: deepfakes, social engineering, and autonomous attacks
Aug 21, 2026Clusters highlight the rise of AI-driven threats including deepfake fraud, AI-enhanced phishing and social engineering, autonomous AI attacks, and AI model sandbox escapes impacting multiple sectors.