Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
26 topicsDrone warfare and counter-drone operations in Ukraine conflict
Oct 4, 2026Clusters highlight expanding drone capabilities, drone strikes in Ukraine, military drone acquisitions, and government counter-drone programs amid rising geopolitical tensions.
AI deepfake scams targeting elections and executives
Oct 4, 2026Multiple clusters report AI deepfake misuse for election interference, executive impersonation, investment fraud, harassment, and legal challenges in victim justice.
Cryptocurrency theft, laundering, and sanctions evasion attacks
Oct 4, 2026Multiple clusters describe large-scale crypto exchange hacks, token thefts, laundering via privacy tools, sanctions evasion using cryptocurrency, and post-hack social engineering scams.
AI-driven cyber threats: autonomous agents and prompt injection attacks
Oct 4, 2026Clusters highlight AI-powered attacks, autonomous AI agents breaching systems, prompt injection risks, AI-accelerated vulnerability discovery, and AI-enabled social engineering challenging traditional defenses.
Active exploitation of critical RCE vulnerabilities in enterprise software
Oct 4, 2026Multiple clusters report urgent exploitation of critical RCE and zero-day vulnerabilities across enterprise platforms, web frameworks, open-source libraries, and security tools, requiring immediate patching.
State-backed cyber espionage targeting governments and critical infrastructure
Oct 4, 2026Reports detail espionage arrests, surveillance using spyware, gray zone operations, and cyberattacks by China, Russia, and other state actors against political, academic, and infrastructure targets.
Ransomware campaigns with public leaks and law enforcement crackdowns
Oct 4, 2026Multiple ransomware groups conduct attacks on healthcare, legal, real estate, municipal, and critical infrastructure sectors, with ongoing leak site activity and law enforcement interventions.
AI-powered phishing and social engineering with novel evasion tactics
Oct 4, 2026Clusters report phishing attacks abusing trusted software, OAuth token theft, AI-driven social engineering, homoglyph lures, and messaging app impersonation to compromise credentials and accounts.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
647 topicsNo longer detected as trending. Sorted newest archived first.
Ransomware and Malware Campaigns Leveraging Credential Theft and Advanced Network Techniques
Jul 7, 2026Emerging ransomware groups and malware campaigns leverage stolen credentials, operational security lapses, and sophisticated remote execution and persistence methods to compromise diverse sectors including industrial and enterprise environments.
Financial Exploits and Fraud Targeting Cryptocurrency and DeFi Platforms
Jul 7, 2026Crypto and DeFi ecosystems face diverse financial attacks including flash loan exploits, wallet manipulation, smart contract vulnerabilities, and state seizures of illicit assets.
State-Linked Cyber Espionage and Sabotage Targeting Critical Infrastructure and Political Entities
Jul 7, 2026Law enforcement and reports reveal nation-state cyber operations involving espionage, sabotage, and influence campaigns against critical infrastructure, government, media, and political figures amid geopolitical tensions.
This week’s emerging threats and exploits in cryptocurrency and DeFi
Jul 8, 2026Cryptocurrency and DeFi platforms face complex exploits including flash loans, wallet address swapping, SIM swaps, infostealers, and laundering linked to state-backed threat actors, resulting in large-scale thefts and law enforcement seizures.
AI-Driven Offensive Techniques: Prompt Injection, Deepfakes, and Supply Chain Attacks
Jul 5, 2026Emerging AI-powered cyber threats leverage prompt injection, AI-generated deepfakes, SEO poisoning, and attacks on AI software supply chains to conduct sophisticated fraud, misinformation, and exploitation campaigns.
Critical RCE and Privilege Escalation Vulnerabilities Actively Exploited
Jul 5, 2026Multiple clusters report critical software vulnerabilities across open-source, enterprise, cloud-native, and Linux ecosystems that allow attackers to execute code remotely, escalate privileges, or bypass authentication, with active exploitation observed.
Phishing and Account Takeover Campaigns Evolve with Advanced Evasion
Jul 5, 2026Phishing operations increasingly use impersonation, social engineering, AiTM kits, Microsoft 365 collaboration features, and novel evasion methods to deliver malware, remote access trojans, and steal credentials across cloud, crypto, and targeted industries.
Sector-Specific Phishing and Social Engineering Campaigns Exploiting Trusted Brands
Jul 7, 2026Attackers use tailored social engineering tactics including event- and sector-specific lures, brand impersonation, voice phishing, and social media ads to deceive victims and facilitate fraud.
Supply Chain Attacks Target Open-Source Developer Accounts and Package Ecosystems
Jul 5, 2026Threat actors compromise open-source maintainer accounts and exploit vulnerabilities in package registries and plugin marketplaces to distribute malicious code and malware across software supply chains.
Major Data Breaches Expose Sensitive Information Triggering Legal Actions
Jul 5, 2026Multiple large-scale data breaches impact healthcare, education, nonprofit, and corporate sectors, exposing personal and financial data and triggering investigations, settlements, and regulatory actions.
Ransomware and Malware Campaigns Employ Novel Delivery and Evasion Techniques
Jul 5, 2026Ransomware groups increasingly use autonomous AI, browser extensions, proxy networks, DLL sideloading, and initial access brokers to disrupt critical infrastructure, healthcare, and enterprise endpoints with advanced evasion and delivery methods.
Cryptocurrency and DeFi Under Sustained Cyberattack with New Exploits
Jul 5, 2026Crypto platforms, wallets, and decentralized finance projects face exploits including signature flaws, SIM swap, supply chain compromises, blockchain bridge breaches, and state asset seizures, prompting governance reforms and highlighting evolving threats.
Critical RCE and Privilege Escalation Exploits in Linux and Enterprise Software
Jul 2, 2026Multiple critical vulnerabilities enabling remote code execution and privilege escalation have been disclosed and actively exploited across open-source Linux components, Fedora, SUSE, and widely used enterprise applications.
Cryptocurrency Exploits, Thefts, and Law Enforcement Crackdowns
Jul 2, 2026Threat actors continue to target cryptocurrency users, DeFi platforms, and blockchain bridges through malware, scams, SIM swaps, and supply-chain attacks, while law enforcement agencies conduct seizures and crackdowns on illicit crypto activities.
State-Sponsored Espionage and Sabotage Targeting Critical Sectors
Jul 2, 2026Nation-state actors, including Russian and Chinese-linked groups, conduct sophisticated espionage, sabotage, and influence operations against political figures, media, energy, water utilities, and election infrastructure.
Malicious Open-Source Packages and AI Supply Chain Threats
Jul 7, 2026Clusters highlight risks from malicious open-source packages delivering malware, AI-related supply chain threats, and domain squatting impacting software and AI ecosystems.
Microsoft 365 and Cloud Service Exploits Including MFA Bypass
Jul 2, 2026Attackers increasingly exploit Microsoft 365 environments and enterprise cloud platforms through password spraying, phishing kits bypassing MFA, and identity-based attacks to gain unauthorized access.
Advanced Evasion Phishing and Social Engineering Campaigns
Jul 2, 2026Recent phishing and social engineering operations employ novel evasion techniques such as authentication laundering and AI-enhanced methods to target enterprises, hospitality, financial users, and consumers across multiple platforms including Microsoft 365.
This Week’s Law Enforcement Disruptions of Cybercrime Infrastructure
Jul 1, 2026Coordinated police operations target cybercrime forums, ransomware infrastructure, online fraud, gambling syndicates, and cybercrime-as-a-service platforms to disrupt illicit activities.
This Week’s AI-Driven Cyber Offense and Defense Advances
Jul 1, 2026Recent developments include AI-powered penetration testing, vulnerability discovery, incident response, and emerging AI-enabled attack tools and malware using prompt injection and evasion techniques.
Novel Phishing and Social Engineering Campaigns Exploiting Trust and Urgency
Jul 1, 2026Attackers increasingly use social engineering tactics including QR code scams, RAT-laden emails, fraudulent AI tenants, and targeted campaigns against tourists and high-profile individuals.
Ransomware Campaigns Using Novel Delivery and Network Exploits
Jul 1, 2026Emerging ransomware operations use innovative delivery techniques such as SEO poisoning, malware-based proxies, browser extensions, and actively exploit network and firewall vulnerabilities.
Active Exploitation of Critical RCE and Privilege Escalation Vulnerabilities
Jul 1, 2026Multiple critical vulnerabilities enabling remote code execution and privilege escalation in widely used open-source and enterprise software are being actively exploited by attackers.
Ransomware Campaigns Using Novel Delivery and Access Exploitation
Jul 2, 2026Ransomware groups are adopting novel infiltration methods including SEO poisoning, malware-based proxy networks, exploitation of firewall vulnerabilities, malicious browser extensions, and access broker backdoors to target enterprises and critical infrastructure.