Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
26 topicsDrone warfare and counter-drone operations in Ukraine conflict
Oct 4, 2026Clusters highlight expanding drone capabilities, drone strikes in Ukraine, military drone acquisitions, and government counter-drone programs amid rising geopolitical tensions.
AI deepfake scams targeting elections and executives
Oct 4, 2026Multiple clusters report AI deepfake misuse for election interference, executive impersonation, investment fraud, harassment, and legal challenges in victim justice.
Cryptocurrency theft, laundering, and sanctions evasion attacks
Oct 4, 2026Multiple clusters describe large-scale crypto exchange hacks, token thefts, laundering via privacy tools, sanctions evasion using cryptocurrency, and post-hack social engineering scams.
AI-driven cyber threats: autonomous agents and prompt injection attacks
Oct 4, 2026Clusters highlight AI-powered attacks, autonomous AI agents breaching systems, prompt injection risks, AI-accelerated vulnerability discovery, and AI-enabled social engineering challenging traditional defenses.
Active exploitation of critical RCE vulnerabilities in enterprise software
Oct 4, 2026Multiple clusters report urgent exploitation of critical RCE and zero-day vulnerabilities across enterprise platforms, web frameworks, open-source libraries, and security tools, requiring immediate patching.
State-backed cyber espionage targeting governments and critical infrastructure
Oct 4, 2026Reports detail espionage arrests, surveillance using spyware, gray zone operations, and cyberattacks by China, Russia, and other state actors against political, academic, and infrastructure targets.
Ransomware campaigns with public leaks and law enforcement crackdowns
Oct 4, 2026Multiple ransomware groups conduct attacks on healthcare, legal, real estate, municipal, and critical infrastructure sectors, with ongoing leak site activity and law enforcement interventions.
AI-powered phishing and social engineering with novel evasion tactics
Oct 4, 2026Clusters report phishing attacks abusing trusted software, OAuth token theft, AI-driven social engineering, homoglyph lures, and messaging app impersonation to compromise credentials and accounts.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
647 topicsNo longer detected as trending. Sorted newest archived first.
AI-enhanced phishing and voice-based social engineering campaigns
Aug 5, 2026Phishing and social engineering attacks increasingly leverage AI-generated content, impersonation, voice phishing (vishing), typo-squatting, and real-time hijacking to enable account takeovers across sectors.
AI-enhanced phishing and social engineering targeting enterprise and finance
Aug 3, 2026Phishing and social engineering attacks increasingly leverage AI-generated content, brand impersonation, vishing, and collaboration platforms to compromise corporate accounts, finance teams, and diverse sectors, often escalating into large-scale financial fraud.
Ransomware campaigns disrupt critical infrastructure and political targets
Aug 1, 2026Ransomware groups increasingly focus on manufacturing, critical infrastructure, government, and political websites using double extortion, supply chain breaches, and disruptive attacks causing operational and reputational damage.
Ransomware and disruptive cyberattacks hit critical infrastructure and political targets
Jul 31, 2026Clusters report ransomware campaigns impacting manufacturing, critical infrastructure, enterprises, and government or high-profile websites using double extortion, supply chain breaches, and politically motivated defacements.
Ransomware Double Extortion and Supply Chain Attacks
Aug 2, 2026Clusters describe ransomware groups exploiting critical vulnerabilities, targeting supply chains and data exchange platforms, and conducting politically motivated website defacements and ransom demands.
This Week’s AI-Driven Cyber Offense and Defense Innovations
Aug 2, 2026Clusters cover AI-powered vulnerability detection, automated remediation, AI-assisted offensive cyber campaigns, prompt injection attacks, autonomous AI agent intrusions, AI model sandbox escapes, and AI-related vulnerabilities impacting software development and fraud.
Military GPS jamming and electronic warfare in Ukraine-Russia conflict
Aug 5, 2026Clusters highlight military GPS jamming tests, drone strike activities, and navigation disruptions linked to electronic warfare in conflict zones such as Ukraine and Russia.
Ransomware campaigns escalate double extortion and evasion tactics
Aug 5, 2026Recent ransomware attacks increasingly employ double extortion tactics and use browser-based evasion and remote access trojans to bypass detection and pressure victims.
Recent Ransomware Attacks on Industrial and Critical Infrastructure
Aug 4, 2026Clusters report ransomware attacks causing operational disruption and data breaches in manufacturing, rail, healthcare, and other critical infrastructure sectors, often involving double extortion tactics.
Cyberattacks silence and harass exiled media and activists
Jul 31, 2026Authoritarian regimes and threat actors use cyberattacks such as DDoS and AI-generated deepfake scams to silence exiled journalists, activists, and impersonate officials for harassment and fraud.
Ransomware and destructive malware targeting critical infrastructure and OT
Aug 3, 2026Ransomware gangs and destructive malware campaigns increasingly target industrial control systems, utilities, and OT environments causing operational disruption and prompting cybersecurity resilience enhancements.
Messaging and collaboration platform exploits enable persistent espionage
Aug 1, 2026Threat actors exploit vulnerabilities in messaging apps, email platforms like Outlook Web Access, Zimbra, and collaboration tools to maintain persistent access and conduct targeted espionage campaigns.
Espionage and malware delivery via messaging and collaboration platforms
Aug 3, 2026Threat actors exploit vulnerabilities in Microsoft Outlook Web Access, Microsoft 365 APIs, Signal backups, and collaboration platforms to maintain persistent access, exfiltrate data, and conduct espionage.
Persistent Email and Collaboration Platform Exploitation
Aug 2, 2026Multiple campaigns exploit vulnerabilities in Outlook Web Access, email, and collaboration tools to maintain long-term access and conduct espionage despite remediation efforts.
State-Linked Espionage and Cyberattacks on Government and Infrastructure
Aug 2, 2026Clusters highlight state-sponsored cyber espionage campaigns, advanced malware use, exploitation of messaging and collaboration platform vulnerabilities, and cyberattacks disrupting critical infrastructure and essential services.
State-linked cyber espionage hits government, defense, and open source
Aug 1, 2026State-sponsored groups conduct cyber espionage, supply chain attacks, and influence operations targeting government, defense sectors, and open source software infrastructure using malware, botnets, and email platform exploits.
Recent Phishing and Social Engineering Campaigns Using Collaboration Tools and Deepfakes
Aug 4, 2026Multiple clusters report sophisticated phishing and vishing attacks targeting financial, enterprise, and high-value sectors using impersonation, social engineering, AI-driven deepfakes, and collaboration tools like Microsoft Teams.
AI-enhanced phishing campaigns with brand impersonation and evasion
Jul 30, 2026Phishing attacks increasingly leverage AI-generated content, trusted platform impersonation, social engineering, and novel evasion methods to enable account takeovers, financial fraud, and large-scale scams.
AI-Powered Phishing and Brand Impersonation Campaigns
Aug 2, 2026Phishing operations increasingly use AI-generated content, impersonate trusted organizations and brands, and employ sophisticated social engineering to steal credentials and enable account takeovers across diverse sectors.
AI-powered phishing and impersonation enable account takeovers
Aug 1, 2026Phishing attacks increasingly use AI-generated content and brand impersonation to deceive targets, facilitating credential theft, account hijacking, and evolving phishing infrastructure takedowns.
State-backed cyber espionage and sabotage targeting governments and critical infrastructure
Jul 30, 2026Clusters describe state-backed cyber operations involving espionage, sabotage, spyware campaigns, zero-day exploits, and surveillance targeting government entities, critical infrastructure, political figures, and dissidents.
Autonomous AI agents driving multi-stage software and supply chain attacks
Jul 30, 2026Reports highlight autonomous AI agents conducting multi-stage intrusions, AI systems exploiting zero-days in software supply chains, vulnerabilities in AI platforms, and AI-assisted offensive tools used in cyberattacks.
Recent Credential Theft and Account Takeover Campaigns
Aug 4, 2026Clusters report campaigns stealing credentials and compromising enterprise VPNs, firewalls, and customer accounts through phishing, malware, and credential stuffing attacks.
AI-driven disinformation and deepfake campaigns targeting politics
Aug 5, 2026Clusters describe AI-generated deepfake videos, synthetic content, and misinformation campaigns aimed at influencing elections, political discourse, and public opinion.