Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
26 topicsDrone warfare and counter-drone operations in Ukraine conflict
Oct 4, 2026Clusters highlight expanding drone capabilities, drone strikes in Ukraine, military drone acquisitions, and government counter-drone programs amid rising geopolitical tensions.
AI deepfake scams targeting elections and executives
Oct 4, 2026Multiple clusters report AI deepfake misuse for election interference, executive impersonation, investment fraud, harassment, and legal challenges in victim justice.
Cryptocurrency theft, laundering, and sanctions evasion attacks
Oct 4, 2026Multiple clusters describe large-scale crypto exchange hacks, token thefts, laundering via privacy tools, sanctions evasion using cryptocurrency, and post-hack social engineering scams.
AI-driven cyber threats: autonomous agents and prompt injection attacks
Oct 4, 2026Clusters highlight AI-powered attacks, autonomous AI agents breaching systems, prompt injection risks, AI-accelerated vulnerability discovery, and AI-enabled social engineering challenging traditional defenses.
Active exploitation of critical RCE vulnerabilities in enterprise software
Oct 4, 2026Multiple clusters report urgent exploitation of critical RCE and zero-day vulnerabilities across enterprise platforms, web frameworks, open-source libraries, and security tools, requiring immediate patching.
State-backed cyber espionage targeting governments and critical infrastructure
Oct 4, 2026Reports detail espionage arrests, surveillance using spyware, gray zone operations, and cyberattacks by China, Russia, and other state actors against political, academic, and infrastructure targets.
Ransomware campaigns with public leaks and law enforcement crackdowns
Oct 4, 2026Multiple ransomware groups conduct attacks on healthcare, legal, real estate, municipal, and critical infrastructure sectors, with ongoing leak site activity and law enforcement interventions.
AI-powered phishing and social engineering with novel evasion tactics
Oct 4, 2026Clusters report phishing attacks abusing trusted software, OAuth token theft, AI-driven social engineering, homoglyph lures, and messaging app impersonation to compromise credentials and accounts.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
647 topicsNo longer detected as trending. Sorted newest archived first.
Ransomware Double Extortion and Insider Collusion Campaigns
Jul 23, 2026Clusters highlight ransomware groups using double extortion tactics, insider facilitation, dark web coordination, kernel driver exploits, and social engineering targeting enterprise environments.
Ransomware and extortion campaigns disrupt industrial, healthcare, and supply chains with new tactics
Jul 28, 2026Ransomware groups increasingly disrupt manufacturing, healthcare, critical infrastructure, and supply networks using double extortion, software supply-chain vulnerabilities, and unconventional corporate targets.
Ransomware double extortion campaigns hit critical infrastructure and industrial sectors
Jul 24, 2026Recent ransomware attacks focus on critical infrastructure and industrial organizations, employing double extortion methods that combine data encryption with threats of public data leaks to maximize ransom demands.
Ransomware double extortion targets unconventional corporate assets
Jul 29, 2026Recent ransomware operations increasingly combine data theft with encryption extortion and exploit non-traditional corporate assets like printers and VPN vulnerabilities.
Advanced threat actors exploit network edge and legacy infrastructure devices this week
Jul 25, 2026Threat actors actively exploit vulnerabilities and persistence mechanisms in network edge devices such as VPNs, firewalls, routers, and legacy firmware to gain access and conduct espionage or ransomware operations.
State-Linked Cyber Espionage Targeting Infrastructure and Political Actors
Jul 23, 2026Clusters describe nation-state affiliated threat actors conducting espionage, deceptive malware campaigns, and cyberattacks against governments, military, critical infrastructure, and geopolitical targets.
Active exploitation of critical vulnerabilities in major enterprise software
Jul 24, 2026Critical remote code execution and privilege escalation vulnerabilities in major enterprise software platforms are actively exploited in the wild, prompting urgent patching and incident response.
Cyberattacks disrupting critical infrastructure and supply chains
Jul 27, 2026Clusters highlight cyber operations causing operational disruptions and sabotage in energy, manufacturing, logistics, nuclear, and space infrastructure sectors amid growing security challenges.
Russian state-linked cyber espionage and hybrid cyber operations targeting critical infrastructure and government
Jul 22, 2026Multiple clusters detail Russian state-sponsored cyber espionage campaigns and hybrid tactics, including drone-enabled attacks, targeting governments, military logistics, and critical infrastructure.
Russian hybrid cyber operations target Ukraine and European interests
Jul 31, 2026Clusters describe Russian cyber activities using fake CAPTCHAs, drone provocations, concealed software origins, and hybrid warfare methods targeting Ukraine, NATO neighbors, and European geopolitical interests.
AI-enhanced phishing and social engineering campaigns with law enforcement takedowns
Jul 22, 2026Clusters describe widespread phishing, voice phishing, and social engineering attacks enhanced by AI techniques, targeting Microsoft 365, financial services, social media, cloud platforms, and cryptocurrency users, alongside law enforcement takedowns.
Espionage malware abusing cloud platforms and insider threats
Jul 27, 2026State-linked espionage campaigns use malware exploiting cloud collaboration tools, social media recruitment, insider data theft, and stealthy tactics to target governments and officials.
State-linked espionage campaigns abusing collaboration platforms, social media recruitment, and spyware targeting political figures
Jul 22, 2026Clusters describe espionage malware leveraging Microsoft 365 APIs, nation-state recruitment via social media, and spyware campaigns targeting politicians and activists linked to geopolitical tensions.
Supply Chain Attacks on Open-Source Packages and Developer Environments
Jul 23, 2026Clusters describe malicious compromises of open-source packages, compromised maintainer accounts, and exploitation of software update and proxy mechanisms to infiltrate developer and production environments.
Supply chain attacks exploiting developer ecosystems and software signing breaches
Jul 22, 2026Clusters reveal supply chain compromises involving malicious packages, hijacked code-signing certificates, container security issues, and AI-driven supply chain attack vectors threatening software integrity.
Recent Supply Chain Attacks on Developer Ecosystems and Insider Threats
Jul 26, 2026Attacks on software supply chains, including malicious packages and compromised code-signing certificates, combined with insider threats and contractor infiltration by state-aligned hackers, threaten software integrity.
Cryptocurrency Fraud, Theft, and Emerging Quantum Threats
Jul 23, 2026Clusters highlight crypto theft via fraud, bridge exploits, fake apps, regulatory challenges, and emerging quantum risks to wallet and blockchain security.
Cryptocurrency ecosystem targeted by fraud, theft, and AI-enabled attacks
Jul 24, 2026Cryptocurrency users and platforms face theft, fraud, token scams, and AI-powered malware campaigns targeting wallets, exchanges, and decentralized finance protocols.
Ransomware and financially motivated cybercrime disrupting critical infrastructure, industrial, and technology sectors
Jul 22, 2026Clusters highlight ransomware and extortion campaigns targeting critical infrastructure, industrial and tech companies, including insider abuse, third-party breaches, data leaks, and cryptocurrency theft with partial recovery efforts.
Investigations expose concealed state ties in cybersecurity tools and espionage campaigns
Jul 25, 2026Investigations uncover software tools linked to Russian security services and report arrests and espionage campaigns tied to state actors targeting governments and sensitive data worldwide.
Enterprise credential theft and session token exfiltration campaigns intensify this week
Jul 25, 2026Malware and phishing operations increasingly focus on stealing browser credentials, session tokens, and enterprise data to facilitate unauthorized access and account takeover.
Law enforcement takedowns and sanctions against cybercriminal groups and surveillance facilitators
Jul 24, 2026Authorities have conducted arrests, sanctions, and prosecutions targeting darknet drug syndicates, phishing fraudsters, ransomware facilitators, and surveillance platform operators linked to human rights abuses.
Cyberattacks disrupting critical infrastructure and supply chains
Jul 16, 2026Cyber threats focus on operational disruptions in logistics, industrial partners, renewable energy, telecommunications, and healthcare sectors, impacting public safety and supply chain continuity.
AI-driven attacks exploiting coding assistants and prompt injection
Jul 16, 2026Emerging attacks leverage AI coding assistants, prompt injection techniques, and AI-powered automation to conduct remote code execution, evade detection, and facilitate cybercrime operations.