Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
26 topicsDrone warfare and counter-drone operations in Ukraine conflict
Oct 4, 2026Clusters highlight expanding drone capabilities, drone strikes in Ukraine, military drone acquisitions, and government counter-drone programs amid rising geopolitical tensions.
AI deepfake scams targeting elections and executives
Oct 4, 2026Multiple clusters report AI deepfake misuse for election interference, executive impersonation, investment fraud, harassment, and legal challenges in victim justice.
Cryptocurrency theft, laundering, and sanctions evasion attacks
Oct 4, 2026Multiple clusters describe large-scale crypto exchange hacks, token thefts, laundering via privacy tools, sanctions evasion using cryptocurrency, and post-hack social engineering scams.
AI-driven cyber threats: autonomous agents and prompt injection attacks
Oct 4, 2026Clusters highlight AI-powered attacks, autonomous AI agents breaching systems, prompt injection risks, AI-accelerated vulnerability discovery, and AI-enabled social engineering challenging traditional defenses.
Active exploitation of critical RCE vulnerabilities in enterprise software
Oct 4, 2026Multiple clusters report urgent exploitation of critical RCE and zero-day vulnerabilities across enterprise platforms, web frameworks, open-source libraries, and security tools, requiring immediate patching.
State-backed cyber espionage targeting governments and critical infrastructure
Oct 4, 2026Reports detail espionage arrests, surveillance using spyware, gray zone operations, and cyberattacks by China, Russia, and other state actors against political, academic, and infrastructure targets.
Ransomware campaigns with public leaks and law enforcement crackdowns
Oct 4, 2026Multiple ransomware groups conduct attacks on healthcare, legal, real estate, municipal, and critical infrastructure sectors, with ongoing leak site activity and law enforcement interventions.
AI-powered phishing and social engineering with novel evasion tactics
Oct 4, 2026Clusters report phishing attacks abusing trusted software, OAuth token theft, AI-driven social engineering, homoglyph lures, and messaging app impersonation to compromise credentials and accounts.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
647 topicsNo longer detected as trending. Sorted newest archived first.
Spike in AI-enabled social engineering and deepfake scams
Jul 16, 2026AI-generated deepfakes, synthetic identities, and AI-enhanced social engineering campaigns increasingly target individuals and enterprises through phishing, vishing, and brand impersonation to steal credentials and commit fraud.
Ransomware campaigns leveraging credential theft and insider collaboration
Jul 16, 2026Ransomware groups increasingly collaborate with credential theft specialists and exploit vulnerabilities in third-party software and insider access to conduct extortion and data theft campaigns affecting government, manufacturing, and small businesses.
Supply chain attacks targeting open-source ecosystems and developers
Jul 16, 2026Threat actors, including North Korean groups, expand supply chain compromises involving npm packages, container security, and open-source developer tools to infiltrate software ecosystems and cause data exposure.
Cryptocurrency and DeFi platform exploits and laundering schemes
Jul 16, 2026Attackers exploit vulnerabilities in blockchain bridges, DeFi governance, and crypto wallets, while sanctioned nations use cryptocurrency for sanctions evasion and laundering through complex schemes.
Cryptocurrency attacks, fraud, and sanctions evasion spike
Jul 14, 2026Clusters highlight crypto wallet and Web3 platform vulnerabilities exploited for large-scale thefts, governance attacks, fraud scams, and use of crypto transactions by sanctioned states to bypass restrictions.
Active exploitation of critical RCE and privilege escalation flaws
Jul 14, 2026Multiple clusters report critical software flaws in widely used infrastructure, open-source, AI tools, and enterprise software that enable remote code execution, privilege escalation, and unauthorized control, with active exploitation observed.
Spike in AI-driven cyberattacks and defenses
Jul 14, 2026Reports highlight the rise of AI-powered cyberattacks including AI-adaptive malware, prompt injection, AI-enabled ransomware, and AI-driven phishing, alongside emerging AI-based security tools and governance efforts.
Russian state-sponsored cyber operations targeting critical infrastructure and allies
Jul 16, 2026Russian FSB and GRU conduct cyberattacks and espionage campaigns against critical infrastructure, military, and government targets across NATO, EU, and Ukraine, accompanied by international diplomatic and legal responses.
Russian cyber operations targeting critical infrastructure and sanctions
Jul 14, 2026Clusters detail Russian state-sponsored cyber espionage and cyberattacks against EU, NATO, and critical infrastructure sectors, alongside related sanctions enforcement by the US and EU.
Phishing and social engineering surge targeting cloud and crypto users
Jul 14, 2026Threat actors employ sophisticated phishing, vishing, and social engineering techniques exploiting Microsoft 365, Google Workspace, cryptocurrency wallets, hospitality, and professional users to steal credentials and conduct fraud.
APT campaigns using novel stealth and espionage techniques
Jul 14, 2026APT groups use sophisticated evasion methods including steganography, fileless backdoors, kernel-mode rootkits, and cloud collaboration platforms to conduct espionage targeting military, law enforcement, and critical infrastructure.
AI deepfake and synthetic media threats targeting politics and journalism
Jul 14, 2026Clusters report AI-driven deepfake videos, synthetic media, and disinformation campaigns targeting political leaders, ethnic groups, and journalists, raising concerns over misinformation and public trust.
Ransomware evolution with advanced delivery and evasion techniques
Jul 14, 2026Recent ransomware campaigns increasingly leverage AI, signed kernel drivers, modular toolkits, SEO poisoning, proxy malware, and advanced lateral movement methods to enhance stealth, scale, and impact.
AI-generated disinformation and influence operations
Jul 10, 2026Multiple clusters report AI-driven or foreign-origin online content targeting communities to manipulate social and political narratives.
Emerging AI security risks and governance challenges
Jul 10, 2026Clusters highlight new AI-related security threats, governance solutions, and systemic risks from advanced AI models in enterprises and society.
Emerging covert data exfiltration and insider threat techniques
Jul 14, 2026Novel data theft methods such as pixel-based radio emissions from air-gapped systems are emerging alongside rising insider threats involving collusion and negligent insiders causing significant organizational damage.
Critical vulnerabilities in industrial and operational technology protocols
Jul 10, 2026Several clusters reveal security gaps and critical flaws in industrial protocols and OT environments enabling unauthorized access and control.
Large-scale data breaches exposing sensitive corporate and user information
Jul 10, 2026Multiple incidents involve significant data breaches affecting millions of users and corporate secrets, leading to lawsuits and darknet sales.
AI-powered phishing and social engineering campaigns with advanced evasion
Jul 8, 2026Sophisticated phishing attacks use AI-driven techniques, social engineering, brand impersonation, MFA bypass, RATs, and novel delivery methods targeting sectors including hospitality, public, and private organizations.
Active exploitation of critical RCE in enterprise and cloud software
Jul 8, 2026Several widely used enterprise, cloud, and network device platforms face critical remote code execution vulnerabilities that are actively exploited by threat actors to deploy malware and gain unauthorized access.
Critical RCE and Privilege Escalation Exploits in Linux and Enterprise Software
Jul 7, 2026Multiple clusters report critical remote code execution and privilege escalation vulnerabilities actively exploited in widely used Linux components, enterprise platforms, and cloud-native environments requiring urgent patching.
AI-Enhanced Credential Theft and Phishing Campaigns
Jul 7, 2026Sophisticated phishing, social engineering, and infostealer campaigns increasingly use AI-generated content, impersonation, and evasion tactics like AiTM and SIM swapping to steal credentials and compromise cloud, crypto, and enterprise users.
Critical Linux and open-source vulnerabilities exploited this week
Jul 8, 2026Multiple advisories and active exploitations reveal critical vulnerabilities in Linux kernels, Fedora, SUSE, and widely used open-source libraries that allow privilege escalation, container escapes, and remote code execution requiring urgent patching.
Ransomware evolution with new delivery and automation techniques
Jul 8, 2026Ransomware groups increasingly leverage AI automation, SEO poisoning, proxy networks, and new backdoors deployed by initial access brokers to infiltrate and persist in critical infrastructure and enterprise environments.