Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
27 topics
State-backed cyber espionage and interference amid Russia-Ukraine and other conflicts
Oct 3, 2026Clusters cover espionage arrests, foreign interference, hybrid warfare, and state-backed cyber operations targeting critical infrastructure, government agencies, and journalists, especially linked to Russia, Iran, China, North Korea, and the Ukraine-Russia conflict.
Active exploitation of critical RCE vulnerabilities in WordPress, Citrix, and Linux
Oct 3, 2026Multiple clusters report on critical remote code execution (RCE) vulnerabilities in widely used enterprise, open-source, and infrastructure software—including WordPress, Citrix, Fedora, and Linux components—that are actively exploited in the wild.
Surge in AI-driven autonomous cyber attacks and account theft
Oct 3, 2026Clusters highlight expanding AI-powered cyber threats including autonomous AI agents bypassing controls, AI account theft, AI-enabled phishing and social engineering, AI-driven malware automation, and AI-related governance challenges in enterprise environments.
Spike in AI deepfake fraud and disinformation campaigns
Oct 3, 2026Multiple clusters highlight the rise of AI-generated deepfakes and synthetic media used in social engineering, election interference, identity attacks, sexual exploitation, and challenges in victim justice and detection.
Drone warfare and counter-drone operations in Ukraine conflict
Oct 3, 2026Clusters describe military drone strikes targeting Ukrainian infrastructure, investments in autonomous warfare and counter-drone systems, and drone-related criminal conspiracies linked to geopolitical conflicts.
Supply chain attacks via MSPs and malicious npm packages
Oct 3, 2026Clusters discuss supply chain compromises affecting managed service providers and software ecosystems, including malicious npm packages and attacks on widely used libraries and tools.
Recent large-scale cryptocurrency thefts and sanction evasion tactics
Oct 3, 2026Clusters describe large-scale cryptocurrency thefts, wallet and token exploits, laundering via privacy coins and decentralized protocols, insider abuse, and sanction evasion linked to state and criminal actors.
AI-driven election interference and deepfake disinformation campaigns
Oct 3, 2026Clusters reveal AI-enabled election scams, voter manipulation, political disinformation, arrests for sedition, and the use of deepfake technology to influence political and social domains.
Active zero-day exploits in Citrix NetScaler and enterprise security products
Oct 3, 2026Several clusters report active exploitation of zero-day vulnerabilities in enterprise infrastructure software and security products including Citrix NetScaler, routers, and access management systems.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
638 topicsNo longer detected as trending. Sorted newest archived first.
State-linked cyber espionage targets critical infrastructure and space assets
Aug 22, 2026Nation-state actors conduct cyber espionage and offensive operations against critical infrastructure sectors, satellite and space-based systems, and national security targets using advanced toolkits and cloud-based frameworks.
AI-enabled cyberattacks: prompt injection, autonomous ops, and AI-driven social engineering
Aug 19, 2026Threat actors increasingly use AI tools for prompt injection attacks, autonomous cyber operations, AI-generated phishing and vishing campaigns, and manipulation of AI systems to automate and enhance attack effectiveness.
Ransomware campaigns adopt blockchain infrastructure and novel evasion
Aug 22, 2026Ransomware groups are expanding data theft operations, adopting stealth evasion techniques like Safe Mode bypass, leveraging critical vulnerabilities, and deploying decentralized blockchain-based recovery methods to evade defenses.
Ransomware and extortion campaigns intensify in industrial and healthcare sectors
Aug 18, 2026Ransomware groups are expanding data theft and extortion efforts with new tactics impacting industrial, public, healthcare, and enterprise organizations, often involving high-profile prosecutions and data leak extortion.
Cryptocurrency ecosystem targeted by phishing and state-backed cyber operations
Aug 18, 2026Cryptocurrency holders and platforms face rising threats from phishing, wrench attacks, malicious developer extensions, regulatory controls, and North Korean state-backed cyber operations.
AI-driven cybercrime surge and novel attack techniques
Aug 18, 2026Cybercriminals increasingly leverage AI for autonomous malware adaptation, AI-driven phishing, identity fraud, token jacking, and exploitation of software vulnerabilities, lowering attacker skill barriers and evolving malware tactics.
Cryptocurrency ecosystem targeted by state-backed actors and cybercriminals using social engineering and fraud
Aug 21, 2026Crypto exchanges, wallets, and developer tools face phishing, data breaches, physical coercion, and theft campaigns orchestrated by nation-state and criminal groups.
Ransomware evolution and extortion targeting cloud, healthcare, and critical infrastructure
Aug 21, 2026Ransomware groups increasingly leverage advanced evasion tactics, blockchain-based recovery, and data theft campaigns impacting cloud platforms, healthcare, supply chains, and critical infrastructure.
Targeted phishing and spyware campaigns hit journalists and activists
Aug 22, 2026Targeted phishing and spyware operations leverage messaging apps and mercenary spyware to surveil and compromise journalists, activists, and political figures.
AI-driven cybercrime surge: autonomous attacks and prompt injection exploits
Aug 17, 2026Emerging threats involve AI models autonomously conducting cyberattacks, exploiting prompt injection vulnerabilities, and enabling sophisticated AI-powered phishing, identity fraud, and malware tactics.
AI-powered phishing and social engineering campaigns escalate
Aug 18, 2026State-backed and criminal actors use AI, cloud services, and messaging apps to conduct sophisticated phishing, social engineering, and disinformation campaigns targeting financial, crypto, journalistic, and public audiences.
AI-powered phishing and social engineering campaigns exploiting messaging apps
Aug 20, 2026Threat actors use AI-generated content, messaging platforms, impersonation scams, and phishing-as-a-service to target consumers, industries, journalists, and travelers, with law enforcement takedowns ongoing.
Nation-state espionage and cyber-kinetic operations targeting critical sectors
Aug 19, 2026APT groups and state-linked actors conduct espionage campaigns using cloud collaboration tools, target drone industry executives, interfere in elections, and execute cyber-kinetic operations including drone warfare and internet disruption.
Critical Linux and Open-Source Privilege Escalation and RCE Exploits
Aug 16, 2026Multiple critical vulnerabilities in Linux distributions and open-source components enable privilege escalation and remote code execution, with active exploitation and urgent patching.
This Week’s Phishing and Social Engineering Campaigns Fueling Account Takeovers
Aug 16, 2026Phishing campaigns exploit novel file formats, trusted platforms, and AI enhancements to conduct social engineering, credential theft, and account hijacking causing significant financial and identity breaches.
This Week’s AI-Powered Cyber Offense and Defense Surges
Aug 16, 2026Clusters cover AI-powered security automation, autonomous cyberattacks, AI-enhanced malware and fraud tactics, prompt injection exploits, and AI model misuse impacting both attack and defense.
Ransomware groups leveraging data theft and extortion across multiple sectors
Aug 17, 2026Ransomware campaigns increasingly combine large-scale data breaches with extortion tactics targeting healthcare, logistics, sports, municipalities, and multinational corporations worldwide.
Ransomware Data Theft and Evasion Tactics Targeting Critical Sectors
Aug 16, 2026Ransomware campaigns increasingly combine large-scale data theft for extortion, novel evasion methods including blockchain-based recovery, and attacks on healthcare, infrastructure, and enterprises.
Cl0p and ShinyHunters ransomware data theft and extortion surge this week
Aug 15, 2026Ransomware actors like Cl0p and ShinyHunters are increasingly stealing large volumes of sensitive data and disrupting operations in healthcare, critical infrastructure, supply chains, and diverse public and private sectors.
Russia–China nation-state cyber operations targeting critical infrastructure this week
Aug 15, 2026State-linked actors, including Russian and Chinese groups, conduct cyberattacks, espionage, disinformation, and supply chain compromises against government agencies, critical infrastructure, and political figures amid geopolitical conflicts.
State-backed cryptocurrency phishing, fraud, and laundering campaigns this week
Aug 15, 2026Phishing, extortion, and laundering campaigns targeting cryptocurrency users and platforms involve state-backed actors and sophisticated fraud techniques causing significant financial losses and prompting regulatory responses.
AI-driven offensive cyber operations and attack automation
Aug 14, 2026Reports highlight AI-powered cyberattacks including autonomous exploitation, prompt injection, AI agent frameworks abused for coordinated attacks, AI-enabled phishing and social engineering, and AI tools accelerating zero-click and identity fraud attacks.
Windows Zero-Day and Enterprise Software Exploits in Active Use
Aug 16, 2026Threat actors actively exploit zero-day and critical remote code execution vulnerabilities in Windows and widely used enterprise software, enabling unauthorized access and system compromise.
Ransomware and disruptive cyberattacks targeting critical infrastructure and healthcare
Aug 14, 2026Clusters describe ransomware campaigns evolving with decentralized infrastructure, targeting healthcare, water utilities, government agencies, and financial services causing operational disruption, data extortion, and cryptocurrency-based extortion.