Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
27 topics
State-backed cyber espionage and interference amid Russia-Ukraine and other conflicts
Oct 3, 2026Clusters cover espionage arrests, foreign interference, hybrid warfare, and state-backed cyber operations targeting critical infrastructure, government agencies, and journalists, especially linked to Russia, Iran, China, North Korea, and the Ukraine-Russia conflict.
Active exploitation of critical RCE vulnerabilities in WordPress, Citrix, and Linux
Oct 3, 2026Multiple clusters report on critical remote code execution (RCE) vulnerabilities in widely used enterprise, open-source, and infrastructure software—including WordPress, Citrix, Fedora, and Linux components—that are actively exploited in the wild.
Surge in AI-driven autonomous cyber attacks and account theft
Oct 3, 2026Clusters highlight expanding AI-powered cyber threats including autonomous AI agents bypassing controls, AI account theft, AI-enabled phishing and social engineering, AI-driven malware automation, and AI-related governance challenges in enterprise environments.
Spike in AI deepfake fraud and disinformation campaigns
Oct 3, 2026Multiple clusters highlight the rise of AI-generated deepfakes and synthetic media used in social engineering, election interference, identity attacks, sexual exploitation, and challenges in victim justice and detection.
Drone warfare and counter-drone operations in Ukraine conflict
Oct 3, 2026Clusters describe military drone strikes targeting Ukrainian infrastructure, investments in autonomous warfare and counter-drone systems, and drone-related criminal conspiracies linked to geopolitical conflicts.
Supply chain attacks via MSPs and malicious npm packages
Oct 3, 2026Clusters discuss supply chain compromises affecting managed service providers and software ecosystems, including malicious npm packages and attacks on widely used libraries and tools.
Recent large-scale cryptocurrency thefts and sanction evasion tactics
Oct 3, 2026Clusters describe large-scale cryptocurrency thefts, wallet and token exploits, laundering via privacy coins and decentralized protocols, insider abuse, and sanction evasion linked to state and criminal actors.
AI-driven election interference and deepfake disinformation campaigns
Oct 3, 2026Clusters reveal AI-enabled election scams, voter manipulation, political disinformation, arrests for sedition, and the use of deepfake technology to influence political and social domains.
Active zero-day exploits in Citrix NetScaler and enterprise security products
Oct 3, 2026Several clusters report active exploitation of zero-day vulnerabilities in enterprise infrastructure software and security products including Citrix NetScaler, routers, and access management systems.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
638 topicsNo longer detected as trending. Sorted newest archived first.
AI-enhanced phishing and vishing campaigns targeting finance and enterprise
Aug 7, 2026Evolving phishing and voice phishing campaigns leverage AI, brand impersonation, and advanced techniques to compromise enterprise and financial accounts, bypass MFA, and cause significant financial fraud and account takeovers.
State-sponsored espionage targeting critical infrastructure and supply chains
Aug 8, 2026Clusters detail nation-state espionage campaigns using spyware, backdoored routers, supply chain attacks, and targeting of military, submarine cable, and satellite communication infrastructure.
State-Sponsored Espionage and Supply Chain Compromises Using Spyware and Backdoors
Aug 9, 2026Nation-state actors conduct targeted surveillance, espionage, and supply chain attacks involving spyware, backdoored routers, malicious packages, and persistent malware implants.
State-sponsored espionage using spyware, backdoors, and physical threats
Aug 12, 2026Clusters cover state-linked spyware deployments, backdoors, assassination plots, and cyber operations targeting activists, executives, governments, and critical infrastructure.
Ransomware and disruptive attacks targeting public sector and critical infrastructure
Aug 12, 2026Ransomware and cyberattacks increasingly impact government agencies, telecoms, water utilities, manufacturing, and automotive sectors causing operational disruptions.
Ransomware Operations and Law Enforcement Takedowns Amid Geopolitical Conflicts
Aug 9, 2026Clusters cover ransomware campaigns linked to geopolitical tensions, their disruptive impacts on critical infrastructure, and coordinated law enforcement actions against operators.
Spike in ransomware and DDoS attacks amid law enforcement takedowns
Aug 8, 2026Reports cover a surge in ransomware and DDoS attacks across sectors, including state-aligned groups, alongside law enforcement actions disrupting cybercrime infrastructure.
Supply chain attacks on software packages, VPN apps, and plugin registries
Aug 7, 2026Threat actors increasingly compromise software supply chains, including packages, VPN applications, and plugin registries, to distribute malware and backdoors with widespread impact.
Supply chain attacks via malicious and counterfeit software packages
Aug 17, 2026Attackers compromise software supply chains and developer ecosystems by distributing malicious, counterfeit, or backdoored packages affecting npm, VPN apps, and developer tools.
This week’s state-linked espionage and supply chain strikes on government and critical sectors
Aug 6, 2026Clusters describe nation-state cyber operations including espionage, supply chain compromises, spyware targeting officials and activists, and zero-day exploits against government, critical infrastructure, and software ecosystems.
Supply Chain Attacks Targeting Developer Ecosystems and VPN Software
Aug 9, 2026Multiple clusters reveal supply chain compromises involving malicious or counterfeit packages, VPN apps, and tightened API key policies impacting software development and distribution.
AI-powered cyber offense and defense campaigns this week
Aug 6, 2026Reports cover AI-powered attack techniques such as deepfakes, prompt injection, autonomous campaigns, and AI-enhanced defense tools for vulnerability management, pentesting, and governance.
Recent malware and theft campaigns targeting cryptocurrency platforms
Aug 6, 2026Clusters highlight malware campaigns, social engineering scams, wallet credential theft, platform hacks, and evolving cybercrime tactics impacting crypto wallets, exchanges, and blockchain platforms.
Emerging AI-driven synthetic identity fraud and deepfake disinformation
Aug 11, 2026AI-enabled synthetic identity fraud, deepfake generation, and AI-powered disinformation campaigns manipulate political narratives and executive reputations.
Surge in AI-enabled identity fraud and synthetic identity threats
Aug 5, 2026Generative AI and related technologies are increasingly used to create synthetic identities, enhance phishing attacks, and impersonate workforce members, escalating fraud sophistication.
New AI platform vulnerabilities and AI-driven cyberattacks
Aug 5, 2026Multiple clusters reveal new vulnerabilities, active intrusions, and AI-driven offensive and defensive tools impacting AI agent platforms, workflow servers, and AI-powered cyber operations including zero-day exploitation and prompt injection.
This week’s advanced phishing and credential theft campaigns
Aug 6, 2026Multiple clusters reveal advanced phishing techniques including AI-enhanced voice phishing, device-code MFA bypass, targeting of financial, corporate, and cryptocurrency users leading to credential theft and account hijacking.
Supply chain attacks via malicious packages and poisoned developer tools
Aug 5, 2026Attackers exploit developer trust by compromising open-source packages, software plugins, and development tools to infiltrate supply chains and harvest data.
Advanced malware campaigns leveraging novel loaders targeting law firms, gamers, and developers
Aug 14, 2026Reports detail sophisticated malware using innovative obfuscation, new loaders, and targeting sectors such as law firms, gamers, and developers with supply chain and infostealer tactics.
Advanced malware campaigns using novel delivery and social engineering
Aug 7, 2026Emerging malware campaigns use social engineering, fake updates, malicious terminal commands, image-based loaders, and botnets leveraging blockchain and hardware features for stealth and persistence.
Novel malware delivery via obfuscation and supply chain compromises
Aug 8, 2026Clusters highlight malware hidden in cached images, supply-chain injected scripts targeting crypto wallets, and new malware exploiting emerging authentication methods like Google Passkeys.
Multi-million dollar cryptocurrency platform and wallet thefts
Aug 7, 2026Several clusters describe sophisticated attacks on cryptocurrency platforms, wallets, and supply chains resulting in multi-million dollar thefts, including hardware wallet firmware exploits and malware campaigns targeting crypto users.
This Week’s Cryptocurrency Platform Hacks and Wallet Thefts
Aug 4, 2026Clusters detail significant hacks, supply-chain compromises, malware campaigns, and firmware vulnerabilities targeting cryptocurrency platforms, wallets, and users, resulting in multimillion-dollar thefts and regulatory responses.
This week’s AI-driven deepfake and disinformation attacks on political and public figures
Aug 6, 2026Clusters describe AI-generated deepfakes and coordinated disinformation efforts leveraging AI to manipulate political narratives, elections, protests, and executive communications.