Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
26 topics
State-linked cyber espionage and hybrid warfare targeting critical sectors
Oct 1, 2026Clusters describe sophisticated state-sponsored cyber espionage, hybrid warfare activities, and cyberattacks targeting government, defense sectors, critical infrastructure, and geopolitical adversaries amid ongoing conflicts.
Active exploitation of critical RCE vulnerabilities across major software
Oct 1, 2026Multiple clusters report ongoing active exploitation of critical remote code execution (RCE) vulnerabilities across diverse widely used software platforms, including enterprise, infrastructure, and security tools, enabling attackers to execute arbitrary code remotely and escalate privileges.
Surge in AI-enabled social engineering, phishing, and deepfake scams
Oct 1, 2026Clusters highlight the growing use of AI-driven phishing, social engineering, and deepfake impersonations to defraud individuals and organizations, including financial institutions and crypto users, with emerging countermeasures.
Critical auth bypass vulnerabilities disclosed in open-source and industrial software
Oct 1, 2026Several critical authentication and authorization bypass flaws have been disclosed in open-source libraries, industrial control, and IoT devices, enabling unauthorized access, credential theft, and privilege escalation.
Cryptocurrency platform exploits and laundering via privacy coins
Oct 1, 2026Multiple incidents involve cryptocurrency exchange hacks, smart contract exploits, wallet thefts on various platforms including Apple devices, and laundering of stolen funds using privacy-focused coins.
Ransomware campaigns with combined encryption and data leak extortion
Oct 1, 2026Multiple ransomware groups continue to target organizations across industries and countries, combining encryption attacks with public data leak extortion tactics causing operational disruptions and financial losses.
Phishing and social engineering campaigns exploiting novel vectors and trusted platforms
Oct 1, 2026Threat actors increasingly use innovative phishing techniques leveraging holidays, homoglyph attacks, OAuth flows, QR codes, calendar invites, and trusted communication platforms to harvest credentials and deploy malware.
Security incidents from autonomous AI agents and prompt injection attacks
Oct 1, 2026Multiple incidents and clusters report security challenges from autonomous AI agents causing unauthorized data access, prompt injection attacks, and breaches of sensitive government, health, and enterprise systems.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
621 topicsNo longer detected as trending. Sorted newest archived first.
Phishing and social engineering campaigns exploit AI and emerging vectors
Sep 28, 2026Phishing and social engineering remain primary malware delivery methods, increasingly leveraging AI-generated content, holiday-themed lures, URL spoofing, OAuth flaws, QR codes, calendar invites, and voice/SMS channels to steal credentials and bypass defenses.
Coordinated Ransomware Campaigns with Data Leak Extortion Across Multiple Sectors
Sep 24, 2026Multiple ransomware groups have launched coordinated attacks across healthcare, government, manufacturing, legal, education, and critical infrastructure sectors using sophisticated malware, automation, and exploiting vulnerabilities to extort victims and leak stolen data.
Supply Chain Attacks Targeting Developer Tools and Repositories
Sep 30, 2026Attackers have leveraged compromised npm packages, OAuth token theft, malicious JavaScript injections, and third-party service provider breaches to conduct supply chain attacks affecting software development and enterprise ecosystems.
This Week's Data Breaches Featuring Credential Theft and Government Domain Impersonation
Sep 23, 2026Recent data breaches have exposed sensitive personal and organizational information through stolen credentials, hardcoded tokens, impersonation scams, and spoofed government email domains.
Supply Chain Attacks Exploit Compromised Tokens and Malicious Packages This Week
Sep 23, 2026Cyberattacks increasingly target software supply chains, including npm and private repositories, by exploiting compromised tokens and injecting malicious packages to spread malware and steal credentials.
Supply chain compromises via developer tools and malicious JavaScript
Sep 29, 2026Attackers increasingly exploit trusted software package maintainers, developer ecosystem components like npm and OAuth tokens, and evasive malicious JavaScript campaigns to distribute malware and compromise supply chains affecting web platforms and enterprise environments.
Espionage Operations Target Political Critics and Activists in Recent Campaigns
Sep 23, 2026State-aligned threat actors conduct espionage campaigns using spyware, malware, and compromised devices to surveil activists, dissidents, government entities, and political critics.
Deepfake and AI Synthetic Media Misuse Surges in Scams and Political Disinformation
Sep 23, 2026AI-generated deepfakes and synthetic media are increasingly weaponized for scams, election interference, political disinformation, harassment, and identity validation challenges, prompting legal and detection responses.
Global surge in deepfake disinformation, fraud, and legal challenges
Sep 22, 2026AI-generated deepfakes are increasingly used in political disinformation, fraud schemes, and reputation attacks, prompting legal actions and regulatory responses in multiple regions.
Ransomware campaigns deploying novel exploitation and data leak tactics this week
Sep 22, 2026Multiple ransomware groups are conducting widespread attacks across sectors and regions using advanced exploitation techniques, phishing, and data leak extortion to disrupt operations and demand ransoms.
Cryptocurrency Cybercrime Exploits Wallet Vulnerabilities and Token Fraud in Recent Attacks
Sep 23, 2026Cybercriminals are increasingly targeting cryptocurrency wallets and users through malware, phishing, compromised infrastructure, token exploits, and blockchain-based payload delivery methods.
Cryptocurrency Thefts Exploiting Smart Contract and DeFi Vulnerabilities
Sep 24, 2026Cybercriminals target cryptocurrency platforms through smart contract exploits, DeFi oracle manipulations, crypto wallet malware on mobile devices, and phishing campaigns following third-party breaches, causing significant financial losses.
Surge in AI-driven phishing, deepfakes, and autonomous cyber attacks
Sep 21, 2026Emerging AI-enabled threats encompass AI-assisted phishing and scam campaigns, deepfake-enabled fraud and misinformation, autonomous AI hacking agents, and AI-driven attacker automation targeting enterprises, critical infrastructure, and political sectors.
Espionage and surveillance campaigns via insiders and state-sponsored spyware
Sep 21, 2026Reports highlight espionage activities involving insider recruitment, credential theft, compromised IP and network cameras, low-tech spying methods, and state-sponsored spyware targeting activists, dissidents, and military targets.
Cryptocurrency platform exploits and large-scale financial crimes
Sep 21, 2026Multiple clusters report large-scale cryptocurrency platform vulnerabilities, smart contract exploits, phishing campaigns targeting crypto users, and financial crimes causing multi-million to billion-dollar losses.
Advanced phishing and social engineering campaigns exploiting holiday themes and deception
Sep 21, 2026Sophisticated phishing and social engineering attacks exploit holiday themes, homoglyphs, OAuth abuse, QR codes, voice phishing, and brand impersonation to target financial services, education, telecom, and executives.
AI-enhanced phishing and social engineering campaigns evolving this week
Sep 22, 2026Phishing and social engineering attacks increasingly use AI-generated content, voice phishing, call centers, homoglyphs, and advanced deception techniques to steal credentials and sensitive data across sectors.
Ransomware campaigns with data leaks and advanced evasion across multiple sectors
Sep 21, 2026Multiple ransomware groups have targeted organizations across healthcare, energy, education, government, and critical infrastructure sectors using advanced evasion techniques, VPN and credential exploits, novel malware tools, and data leak extortion.
Deepfake and AI-Generated Content Regulation and Legal Actions in Political and Personal Contexts
Sep 24, 2026Legal rulings and regulatory debates, particularly in India, address the challenges posed by deepfake videos and AI-generated synthetic media used for political disinformation, fraud, and non-consensual personal attacks.
AI-powered phishing, malware, and autonomous cyberattacks escalate
Sep 20, 2026AI technologies are increasingly leveraged by threat actors for phishing with synthetic identities, AI-generated malware, autonomous hacking, deepfake scams, and evolving cybercrime tactics.
Deepfake and AI-driven identity fraud and social engineering spike
Sep 20, 2026Deepfake technology and AI-generated synthetic media are increasingly used for impersonation, political disinformation, investment scams, and social engineering fraud targeting individuals and institutions.
Cryptocurrency cybercrime surges via malware and infrastructure compromise
Sep 20, 2026Malware campaigns and exploits focus on stealing cryptocurrency keys, draining wallets, abusing web APIs, and compromising financial institutions to facilitate crypto theft and fraud.
Active exploitation of critical Linux kernel vulnerabilities
Sep 25, 2026Multiple critical Linux kernel and Oracle Linux vulnerabilities have been disclosed and actively exploited, allowing attackers to escalate privileges or execute arbitrary code on affected systems.
Ransomware campaigns with data theft and multi-sector extortion surge
Sep 20, 2026Multiple ransomware groups launched attacks across various industries combining data exfiltration, automated extortion, and multi-platform targeting to pressure victims and disrupt operations.