Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
27 topics
Active exploitation of critical RCE and privilege escalation zero-days in enterprise and open-source software
Oct 2, 2026Multiple clusters report urgent and active exploitation of critical remote code execution and privilege escalation vulnerabilities across widely used enterprise software, Linux distributions, and open-source libraries, including zero-days and rapid weaponization.
Drone and counter-drone operations in ongoing geopolitical conflicts
Oct 2, 2026Reports cover drone attacks on critical infrastructure, military drone deployments, counter-drone technologies, and related investments amid ongoing regional and maritime conflicts.
AI autonomous agents driving breaches and governance challenges
Oct 2, 2026Clusters describe AI-powered autonomous agents breaching government and healthcare systems, AI-driven cyberattacks, AI-enhanced phishing and scams, and the resulting regulatory and governance challenges.
State-linked espionage and cyber operations targeting governments and critical infrastructure
Oct 2, 2026Multiple clusters highlight espionage campaigns, state-sponsored cyberattacks, surveillance activities, arrests, and law enforcement responses targeting governments, academia, critical infrastructure, and journalists.
Critical zero-day exploits in enterprise network and security products
Oct 2, 2026Multiple clusters report zero-day and critical vulnerabilities in enterprise network devices, security products, and virtualization software being actively exploited to gain unauthorized access and disrupt defenses.
Geopolitical tensions fueling cyber, kinetic, and hybrid warfare including disinformation
Oct 2, 2026Clusters reveal cyberattacks, drone strikes, disinformation campaigns, sanctions, and military escalations linked to conflicts involving Russia, Ukraine, Iran, China, and other actors.
Ransomware and malware campaigns disrupting critical infrastructure and healthcare
Oct 2, 2026Ongoing ransomware and malware campaigns target critical infrastructure, healthcare, government, legal, transportation, and other sectors, often combining extortion, data leaks, and destructive tactics.
AI-enhanced phishing, social engineering, and BEC campaigns
Oct 2, 2026Multiple clusters describe phishing and social engineering attacks targeting healthcare, education, military, and AI sectors using AI-driven deepfakes, QR codes, OAuth flows, and impersonation scams.
Cryptocurrency theft and laundering exploiting privacy protocols and smart contracts
Oct 2, 2026Clusters report large-scale cryptocurrency thefts, laundering through privacy-enhanced protocols, smart contract exploits, and related social engineering scams targeting crypto platforms and wallets.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
629 topicsNo longer detected as trending. Sorted newest archived first.
State-linked cyber espionage and influence operations targeting national security and critical infrastructure
Aug 21, 2026Russian, Chinese, North Korean, and other state actors conduct espionage, influence campaigns, and cyberattacks against government, defense, infrastructure, and allied nations.
Account takeover and session hijacking via novel HTTP desync and MFA bypass techniques this week
Sep 1, 2026New attack techniques exploiting HTTP request smuggling, password reset flows, and password spraying campaigns target cloud platforms enabling account hijacking and credential theft.
Account takeover and session hijacking via novel MFA bypass and web attacks
Aug 21, 2026Emerging threats exploit HTTP desync, MFA bypass phishing, session token theft, and webmail vulnerabilities to hijack accounts and enable payment fraud.
Data breaches exposing sensitive employee, biometric, and customer information from third-party cloud compromises and insider threats
Aug 28, 2026Multiple incidents reveal exposure of employee data, biometric images, and millions of customer records due to unsecured databases, third-party cloud service compromises, and insider data theft aided by social engineering.
Ransomware disrupting critical infrastructure, industrial, and cloud environments
Aug 23, 2026Ransomware groups and state-sponsored actors conduct attacks causing operational disruptions, data theft, and extortion across healthcare, financial services, industrial sectors, and cloud platforms.
Phishing campaigns and law enforcement takedowns with advanced evasion and impersonation
Aug 21, 2026Large-scale phishing operations use AI-generated content, impersonation scams, and trusted platforms to steal credentials and financial data, with ongoing disruptions by authorities.
Ransomware Campaigns Targeting Critical Infrastructure and Finance with Data Theft
Aug 25, 2026Ransomware groups increasingly target critical infrastructure, industrial environments, and financial institutions using advanced evasion methods and expanding data theft across multiple industries.
AI deepfakes and identity fraud driving legal and law enforcement responses
Aug 23, 2026The misuse of AI deepfakes for fraud, scams, and impersonation prompts lawsuits, law enforcement takedowns, and proposals for lawful hacking to combat illegal content and identity abuse.
Ransomware and financially motivated cybercrime targeting critical sectors
Aug 24, 2026Clusters covering ransomware campaigns impacting critical infrastructure, healthcare, supply chains, and cloud platforms, including data theft, extortion, evasion tactics, and emerging decentralized blockchain recovery methods.
Ransomware and financial cybercrime targeting cloud, healthcare, and critical infrastructure
Aug 26, 2026Ransomware groups and cybercriminals increasingly disrupt cloud platforms, healthcare providers, public sector, and critical infrastructure using advanced extortion, data theft, and evasion tactics.
August 2026 critical RCE and privilege escalation vulnerabilities across software ecosystems
Aug 20, 2026Multiple clusters report critical vulnerabilities enabling remote code execution and privilege escalation in enterprise, open-source, Linux, and IoT software actively exploited or urgently patched in August 2026.
Data Breaches in Cloud, Supply Chain, and Third-Party Providers This Week
Aug 25, 2026Several breaches stem from unauthorized access to cloud platforms, supply chain companies, and third-party service providers, exposing large volumes of customer and employee data.
Phishing campaigns exploiting AI-generated content and QR codes
Aug 19, 2026Phishing attacks are evolving to use AI-generated emails, voices, and QR codes to bypass traditional defenses and conduct sophisticated social engineering targeting online accounts and financial platforms.
Ransomware campaigns leveraging access brokers and stealth evasion against critical infrastructure
Aug 19, 2026Ransomware groups collaborate with access brokers to infiltrate critical infrastructure, healthcare, and large enterprises, employing stealth evasion techniques and large-scale data exfiltration to maximize impact.
State-linked cyber espionage targets critical infrastructure and space assets
Aug 22, 2026Nation-state actors conduct cyber espionage and offensive operations against critical infrastructure sectors, satellite and space-based systems, and national security targets using advanced toolkits and cloud-based frameworks.
State-linked cyber espionage and influence operations targeting critical infrastructure
Aug 20, 2026Russian, Iranian, North Korean, and other state actors conduct espionage, influence campaigns, DDoS attacks, and cyber operations against US, European, and allied critical infrastructure and institutions.
AI-enabled cyberattacks: prompt injection, autonomous ops, and AI-driven social engineering
Aug 19, 2026Threat actors increasingly use AI tools for prompt injection attacks, autonomous cyber operations, AI-generated phishing and vishing campaigns, and manipulation of AI systems to automate and enhance attack effectiveness.
Ransomware campaigns adopt blockchain infrastructure and novel evasion
Aug 22, 2026Ransomware groups are expanding data theft operations, adopting stealth evasion techniques like Safe Mode bypass, leveraging critical vulnerabilities, and deploying decentralized blockchain-based recovery methods to evade defenses.
Ransomware and extortion campaigns intensify in industrial and healthcare sectors
Aug 18, 2026Ransomware groups are expanding data theft and extortion efforts with new tactics impacting industrial, public, healthcare, and enterprise organizations, often involving high-profile prosecutions and data leak extortion.
Cryptocurrency ecosystem targeted by phishing and state-backed cyber operations
Aug 18, 2026Cryptocurrency holders and platforms face rising threats from phishing, wrench attacks, malicious developer extensions, regulatory controls, and North Korean state-backed cyber operations.
AI-driven cybercrime surge and novel attack techniques
Aug 18, 2026Cybercriminals increasingly leverage AI for autonomous malware adaptation, AI-driven phishing, identity fraud, token jacking, and exploitation of software vulnerabilities, lowering attacker skill barriers and evolving malware tactics.
Cryptocurrency ecosystem targeted by state-backed actors and cybercriminals using social engineering and fraud
Aug 21, 2026Crypto exchanges, wallets, and developer tools face phishing, data breaches, physical coercion, and theft campaigns orchestrated by nation-state and criminal groups.
Ransomware evolution and extortion targeting cloud, healthcare, and critical infrastructure
Aug 21, 2026Ransomware groups increasingly leverage advanced evasion tactics, blockchain-based recovery, and data theft campaigns impacting cloud platforms, healthcare, supply chains, and critical infrastructure.
Targeted phishing and spyware campaigns hit journalists and activists
Aug 22, 2026Targeted phishing and spyware operations leverage messaging apps and mercenary spyware to surveil and compromise journalists, activists, and political figures.