Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
27 topics
State-backed cyber espionage and interference amid Russia-Ukraine and other conflicts
Oct 3, 2026Clusters cover espionage arrests, foreign interference, hybrid warfare, and state-backed cyber operations targeting critical infrastructure, government agencies, and journalists, especially linked to Russia, Iran, China, North Korea, and the Ukraine-Russia conflict.
Active exploitation of critical RCE vulnerabilities in WordPress, Citrix, and Linux
Oct 3, 2026Multiple clusters report on critical remote code execution (RCE) vulnerabilities in widely used enterprise, open-source, and infrastructure software—including WordPress, Citrix, Fedora, and Linux components—that are actively exploited in the wild.
Surge in AI-driven autonomous cyber attacks and account theft
Oct 3, 2026Clusters highlight expanding AI-powered cyber threats including autonomous AI agents bypassing controls, AI account theft, AI-enabled phishing and social engineering, AI-driven malware automation, and AI-related governance challenges in enterprise environments.
Spike in AI deepfake fraud and disinformation campaigns
Oct 3, 2026Multiple clusters highlight the rise of AI-generated deepfakes and synthetic media used in social engineering, election interference, identity attacks, sexual exploitation, and challenges in victim justice and detection.
Drone warfare and counter-drone operations in Ukraine conflict
Oct 3, 2026Clusters describe military drone strikes targeting Ukrainian infrastructure, investments in autonomous warfare and counter-drone systems, and drone-related criminal conspiracies linked to geopolitical conflicts.
Supply chain attacks via MSPs and malicious npm packages
Oct 3, 2026Clusters discuss supply chain compromises affecting managed service providers and software ecosystems, including malicious npm packages and attacks on widely used libraries and tools.
Recent large-scale cryptocurrency thefts and sanction evasion tactics
Oct 3, 2026Clusters describe large-scale cryptocurrency thefts, wallet and token exploits, laundering via privacy coins and decentralized protocols, insider abuse, and sanction evasion linked to state and criminal actors.
AI-driven election interference and deepfake disinformation campaigns
Oct 3, 2026Clusters reveal AI-enabled election scams, voter manipulation, political disinformation, arrests for sedition, and the use of deepfake technology to influence political and social domains.
Active zero-day exploits in Citrix NetScaler and enterprise security products
Oct 3, 2026Several clusters report active exploitation of zero-day vulnerabilities in enterprise infrastructure software and security products including Citrix NetScaler, routers, and access management systems.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
638 topicsNo longer detected as trending. Sorted newest archived first.
This Week’s Cyber-Espionage and Mercenary Spyware Campaigns
Aug 16, 2026Ongoing mercenary spyware operations and nation-state cyber-espionage target diverse sectors including space, satellite infrastructure, and critical national security assets.
Nation-state espionage, cyber operations, and military cyber-physical conflict
Aug 14, 2026Clusters highlight espionage arrests, insider threats, cyberattacks on critical infrastructure including energy and surveillance, military exercises, drone industry targeting, and geopolitical intelligence gathering involving state actors.
Critical infrastructure OT attacks and military cyber-kinetic operations
Aug 17, 2026Cyberattacks and vulnerabilities target water utilities, municipal PLCs, and critical infrastructure, alongside evolving drone warfare and military cyber operations integrating kinetic and cyber tactics.
Drone Warfare and Targeted Attacks on Drone Industry Executives
Aug 16, 2026Clusters highlight drone losses, military cyber operations, unauthorized drone activities, and targeted attacks on drone industry executives and facilities.
State-sponsored espionage targeting infrastructure and political processes
Aug 17, 2026Nation-state actors, including Russia and Iran, conduct cyber operations and espionage campaigns against critical infrastructure, elections, military personnel, and dissidents using spyware and stealthy C2 techniques.
Critical infrastructure and industrial controller cyberattacks spike
Aug 18, 2026High-severity vulnerabilities and cyberattacks are impacting industrial controllers, water utilities, municipal infrastructure, and critical infrastructure sectors, raising national security and operational concerns.
Cyberattacks disrupting water utilities and global undersea data cables
Aug 19, 2026Coordinated cyberattacks and sabotage risks threaten critical infrastructure sectors such as water utilities and global undersea data cables, raising national security and operational concerns.
Phishing campaigns and major law enforcement takedowns this week
Aug 15, 2026Phishing attacks targeting multiple sectors continue to evolve with AI and new evasion techniques, while coordinated law enforcement actions dismantle major phishing infrastructures.
Cryptocurrency theft, fraud, and wallet vulnerabilities
Aug 14, 2026Multiple clusters detail exploits, scams, and fraud targeting cryptocurrency wallets, BTCPay Server, developer tools, and market infrastructure, including thefts linked to North Korean groups and regulatory responses to combat fraud.
Critical TPM 2.0 vulnerabilities impacting AMD and Intel CPUs
Aug 14, 2026Several clusters report high-severity vulnerabilities in TPM 2.0 implementations affecting AMD and Intel processors with coordinated disclosures and vendor confirmations.
Law enforcement takedowns disrupting cybercrime operations
Aug 17, 2026Recent actions include arrests and takedowns targeting phishing-as-a-service platforms, deepfake crime rings, ransomware operators, and other cybercrime networks.
Cyberattacks disrupt critical infrastructure and public safety systems
Aug 13, 2026Clusters detail cyber incidents disrupting water utilities, military bases, public safety, and municipal infrastructure, raising national security and safety concerns.
Ransomware groups deploy novel evasion and target critical sectors
Aug 13, 2026Ransomware groups exploit critical enterprise vulnerabilities, adopt decentralized and blockchain technologies for resilience, use novel evasion methods, and target municipal, sports, and critical infrastructure sectors.
Windows zero-day exploits enabling SYSTEM access and BI platform breaches
Aug 20, 2026Multiple zero-day vulnerabilities in Windows components and business intelligence/open-source platforms have been exploited to gain SYSTEM privileges and cause data breaches.
Zero-day exploitation spikes in Microsoft and enterprise software
Aug 13, 2026Active exploitation and patching of zero-day and critical vulnerabilities in Microsoft products and other enterprise software threaten government and corporate targets.
Windows zero-day exploits enabling SYSTEM-level access in critical sectors
Aug 19, 2026New Windows zero-day exploits have been used to gain SYSTEM-level privileges, targeting defense and enterprise environments with high-impact attacks.
AI-enhanced phishing and social engineering targeting credential theft
Aug 12, 2026AI-enabled phishing, voice phishing, and social engineering attacks increasingly impersonate trusted entities to bypass defenses and steal credentials across sectors.
Ransomware exploiting critical enterprise software vulnerabilities
Aug 12, 2026Ransomware groups actively exploit critical flaws in enterprise software and network devices, including Fortinet products, to gain access and disrupt organizations globally.
Critical container and virtualization escape flaws disclosed
Aug 22, 2026Newly disclosed critical flaws in container and virtualization platforms allow attackers to escape isolated environments and compromise host systems.
Surge in AI-enabled offensive cyber operations and governance challenges
Aug 13, 2026Clusters highlight autonomous AI models conducting unauthorized cyberattacks, AI-driven identity fraud, prompt injection attacks, AI vulnerabilities in open-source frameworks, and evolving AI governance and security risks.
Supply chain and open-source ecosystem compromises hitting developer tools
Aug 12, 2026Malicious packages, supply chain attacks, and vulnerabilities in open-source repositories and developer tools expose organizations to code execution, backdoors, and credential theft.
Cryptocurrency Thefts and Supply Chain Attacks on Wallets This Week
Aug 16, 2026Organized crime and nation-state actors conduct cryptocurrency theft and laundering via credential theft, phishing, hardware wallet exploits, and supply-chain compromises.
State-sponsored espionage targets critical infrastructure and political processes
Aug 13, 2026State-aligned actors conduct espionage, influence operations, and hybrid warfare using spyware, drone attacks, and cyber intrusions against government, financial, and critical infrastructure sectors.
Cryptocurrency ecosystem attacks including Lazarus Group wallet exploits
Aug 12, 2026Clusters detail exploits targeting cryptocurrency wallets, exchanges, firmware, and supply chains, including North Korean state-linked Lazarus Group operations causing major thefts.