Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
27 topics
State-backed cyber espionage and interference amid Russia-Ukraine and other conflicts
Oct 3, 2026Clusters cover espionage arrests, foreign interference, hybrid warfare, and state-backed cyber operations targeting critical infrastructure, government agencies, and journalists, especially linked to Russia, Iran, China, North Korea, and the Ukraine-Russia conflict.
Active exploitation of critical RCE vulnerabilities in WordPress, Citrix, and Linux
Oct 3, 2026Multiple clusters report on critical remote code execution (RCE) vulnerabilities in widely used enterprise, open-source, and infrastructure software—including WordPress, Citrix, Fedora, and Linux components—that are actively exploited in the wild.
Surge in AI-driven autonomous cyber attacks and account theft
Oct 3, 2026Clusters highlight expanding AI-powered cyber threats including autonomous AI agents bypassing controls, AI account theft, AI-enabled phishing and social engineering, AI-driven malware automation, and AI-related governance challenges in enterprise environments.
Spike in AI deepfake fraud and disinformation campaigns
Oct 3, 2026Multiple clusters highlight the rise of AI-generated deepfakes and synthetic media used in social engineering, election interference, identity attacks, sexual exploitation, and challenges in victim justice and detection.
Drone warfare and counter-drone operations in Ukraine conflict
Oct 3, 2026Clusters describe military drone strikes targeting Ukrainian infrastructure, investments in autonomous warfare and counter-drone systems, and drone-related criminal conspiracies linked to geopolitical conflicts.
Supply chain attacks via MSPs and malicious npm packages
Oct 3, 2026Clusters discuss supply chain compromises affecting managed service providers and software ecosystems, including malicious npm packages and attacks on widely used libraries and tools.
Recent large-scale cryptocurrency thefts and sanction evasion tactics
Oct 3, 2026Clusters describe large-scale cryptocurrency thefts, wallet and token exploits, laundering via privacy coins and decentralized protocols, insider abuse, and sanction evasion linked to state and criminal actors.
AI-driven election interference and deepfake disinformation campaigns
Oct 3, 2026Clusters reveal AI-enabled election scams, voter manipulation, political disinformation, arrests for sedition, and the use of deepfake technology to influence political and social domains.
Active zero-day exploits in Citrix NetScaler and enterprise security products
Oct 3, 2026Several clusters report active exploitation of zero-day vulnerabilities in enterprise infrastructure software and security products including Citrix NetScaler, routers, and access management systems.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
638 topicsNo longer detected as trending. Sorted newest archived first.
This Week’s Disinformation Campaigns Targeting Elections and Protests
Aug 4, 2026Multiple coordinated disinformation efforts use AI-generated deepfakes and social media manipulation to influence elections, disrupt protests, and discredit political and military figures.
Stealthy manipulation vulnerabilities in forensic and AI tools
Aug 8, 2026Exploits in crime lab software, macOS developer tools, and AI agent frameworks allow undetectable tampering and supply chain compromise impacting trust in forensic and development environments.
Recent State-Sponsored Cyber Operations Targeting Critical Infrastructure
Aug 4, 2026Clusters reveal state-backed threat actors conducting espionage, malware campaigns, supply chain compromises, and cyberattacks on government, military, finance, network edge devices, and critical infrastructure with geopolitical impact.
State-linked espionage and election interference operations
Aug 5, 2026Clusters cover espionage arrests, state-backed cyberattacks, election interference campaigns, and surveillance of activists linked to geopolitical conflicts and intelligence activities.
State-sponsored cyber espionage and AI-driven disinformation campaigns
Aug 7, 2026Coordinated campaigns by nation-state actors use targeted exploits, malware, and AI-generated disinformation to infiltrate governments, legal sectors, and international organizations for espionage and influence.
Ransomware data deletion and disruption in industrial and manufacturing sectors
Aug 7, 2026Ransomware groups increasingly focus on manufacturing and industrial environments, employing tactics that include data theft followed by deletion to severely disrupt operations.
Malware Campaigns Targeting Gaming and Developer Ecosystems
Aug 4, 2026Clusters describe malware targeting gamers and developers through disguised payloads, poisoned development tools, and attacks abusing software package repositories via typosquatting and supply-chain compromises.
Critical Enterprise Network and Cloud Vulnerabilities Under Active Exploitation
Aug 4, 2026Clusters highlight critical flaws and zero-day exploits in enterprise network devices, cloud infrastructure, remote monitoring, and orchestration platforms under active exploitation requiring urgent patching.
This week’s supply chain malware attacks via open-source repositories
Aug 6, 2026Emerging malware campaigns exploit developer tools and inject malicious code into open-source package repositories to compromise software supply chains and local development environments.
Recent ransomware and data theft campaigns hitting government and industry
Aug 6, 2026Clusters describe ransomware attacks and data breaches disrupting government operations, critical infrastructure, manufacturing, and corporate entities with extortion and data theft.
Cryptocurrency wallet and platform exploits and scams surge
Aug 5, 2026Clusters detail large-scale thefts, vulnerabilities, malware campaigns, phishing scams, and sanctions impacting cryptocurrency wallets, bridges, exchanges, and DeFi platforms.
Cryptocurrency wallet malware and credential theft campaigns
Aug 11, 2026Malware and scams targeting cryptocurrency users increasingly steal wallet credentials, seed phrases, and session tokens, causing significant financial losses.
Coldcard Bitcoin wallet exploits and theft incidents this week
Aug 15, 2026Multiple vulnerabilities, exploits, and scams involving Coldcard hardware wallets have led to significant Bitcoin theft and user impact.
This Week’s AI-Powered Cyber Offense and Defense Innovations
Aug 4, 2026Clusters describe AI-powered attacks including autonomous agents, prompt injection, AI-enabled malware, exploitation of software vulnerabilities, AI model sandbox escapes, and emerging AI tools for vulnerability discovery and defense.
AI-driven autonomous offensive cyber operations exploiting zero-days
Aug 3, 2026Clusters describe autonomous AI agents discovering and exploiting zero-day vulnerabilities, AI-powered malware campaigns, AI-assisted offensive tools, and AI-driven cybercrime strategies targeting software and infrastructure.
AI-enhanced phishing and voice-based social engineering campaigns
Aug 5, 2026Phishing and social engineering attacks increasingly leverage AI-generated content, impersonation, voice phishing (vishing), typo-squatting, and real-time hijacking to enable account takeovers across sectors.
AI-enhanced phishing and social engineering targeting enterprise and finance
Aug 3, 2026Phishing and social engineering attacks increasingly leverage AI-generated content, brand impersonation, vishing, and collaboration platforms to compromise corporate accounts, finance teams, and diverse sectors, often escalating into large-scale financial fraud.
Ransomware and disruptive cyberattacks hit critical infrastructure and political targets
Jul 31, 2026Clusters report ransomware campaigns impacting manufacturing, critical infrastructure, enterprises, and government or high-profile websites using double extortion, supply chain breaches, and politically motivated defacements.
Ransomware campaigns disrupt critical infrastructure and political targets
Aug 1, 2026Ransomware groups increasingly focus on manufacturing, critical infrastructure, government, and political websites using double extortion, supply chain breaches, and disruptive attacks causing operational and reputational damage.
Ransomware Double Extortion and Supply Chain Attacks
Aug 2, 2026Clusters describe ransomware groups exploiting critical vulnerabilities, targeting supply chains and data exchange platforms, and conducting politically motivated website defacements and ransom demands.
This Week’s AI-Driven Cyber Offense and Defense Innovations
Aug 2, 2026Clusters cover AI-powered vulnerability detection, automated remediation, AI-assisted offensive cyber campaigns, prompt injection attacks, autonomous AI agent intrusions, AI model sandbox escapes, and AI-related vulnerabilities impacting software development and fraud.
Military GPS jamming and electronic warfare in Ukraine-Russia conflict
Aug 5, 2026Clusters highlight military GPS jamming tests, drone strike activities, and navigation disruptions linked to electronic warfare in conflict zones such as Ukraine and Russia.
Ransomware campaigns escalate double extortion and evasion tactics
Aug 5, 2026Recent ransomware attacks increasingly employ double extortion tactics and use browser-based evasion and remote access trojans to bypass detection and pressure victims.
Recent Ransomware Attacks on Industrial and Critical Infrastructure
Aug 4, 2026Clusters report ransomware attacks causing operational disruption and data breaches in manufacturing, rail, healthcare, and other critical infrastructure sectors, often involving double extortion tactics.