Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
26 topicsDrone warfare and counter-drone operations in Ukraine conflict
Oct 4, 2026Clusters highlight expanding drone capabilities, drone strikes in Ukraine, military drone acquisitions, and government counter-drone programs amid rising geopolitical tensions.
AI deepfake scams targeting elections and executives
Oct 4, 2026Multiple clusters report AI deepfake misuse for election interference, executive impersonation, investment fraud, harassment, and legal challenges in victim justice.
Cryptocurrency theft, laundering, and sanctions evasion attacks
Oct 4, 2026Multiple clusters describe large-scale crypto exchange hacks, token thefts, laundering via privacy tools, sanctions evasion using cryptocurrency, and post-hack social engineering scams.
AI-driven cyber threats: autonomous agents and prompt injection attacks
Oct 4, 2026Clusters highlight AI-powered attacks, autonomous AI agents breaching systems, prompt injection risks, AI-accelerated vulnerability discovery, and AI-enabled social engineering challenging traditional defenses.
Active exploitation of critical RCE vulnerabilities in enterprise software
Oct 4, 2026Multiple clusters report urgent exploitation of critical RCE and zero-day vulnerabilities across enterprise platforms, web frameworks, open-source libraries, and security tools, requiring immediate patching.
State-backed cyber espionage targeting governments and critical infrastructure
Oct 4, 2026Reports detail espionage arrests, surveillance using spyware, gray zone operations, and cyberattacks by China, Russia, and other state actors against political, academic, and infrastructure targets.
Ransomware campaigns with public leaks and law enforcement crackdowns
Oct 4, 2026Multiple ransomware groups conduct attacks on healthcare, legal, real estate, municipal, and critical infrastructure sectors, with ongoing leak site activity and law enforcement interventions.
AI-powered phishing and social engineering with novel evasion tactics
Oct 4, 2026Clusters report phishing attacks abusing trusted software, OAuth token theft, AI-driven social engineering, homoglyph lures, and messaging app impersonation to compromise credentials and accounts.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
647 topicsNo longer detected as trending. Sorted newest archived first.
State-Linked Espionage and Sabotage Targeting Critical Infrastructure
Jul 5, 2026Advanced persistent threats and nation-state actors conduct cyber and physical espionage, deploying custom malware and exploiting cloud collaboration platforms to target political entities, energy, and critical infrastructure in geopolitical conflict zones.
This Week’s State-Linked Espionage Targeting Critical Infrastructure and Government
Jul 1, 2026Advanced persistent threats and state actors conduct espionage, sabotage, and surveillance campaigns against government, defense, energy sectors, and messaging platforms using spyware and covert networks.
Spike in AI-enabled cyber threats, deepfake scams, and regulatory crackdowns
Jun 30, 2026Clusters highlight the rise of AI-driven cyber attacks, including deepfake-based fraud targeting vulnerable populations, AI-generated offensive tools, and resulting legislative and law enforcement initiatives.
Surge in advanced phishing campaigns using novel evasion and social engineering
Jun 30, 2026Threat actors employ sophisticated phishing techniques such as AiTM kits, QR code phishing, collaboration platform impersonation, and diverse social engineering tactics targeting multiple industries and consumers.
Cryptocurrency exploits surge via bridge vulnerabilities and illicit funding networks
Jun 30, 2026Clusters report coordinated attacks exploiting cryptocurrency platforms, Layer 2 networks, cross-chain bridges, and smart contract flaws facilitating theft, laundering, and geopolitical cybercrime.
Cryptocurrency Exploits, Fraud, and Law Enforcement Actions This Week
Jul 1, 2026Exploits targeting blockchain and DeFi platforms, social engineering attacks on wallets and exchanges, malware campaigns, and law enforcement actions disrupting illicit crypto activities are prominent.
Major data breaches expose sensitive personal, health, and financial information
Jun 30, 2026Multiple incidents involve unauthorized access and data leaks affecting healthcare, financial services, telecommunications, education, and government sectors, compromising personal and organizational data.
Law Enforcement Takedowns and Regulatory Actions Disrupt Cybercrime
Jul 2, 2026Coordinated law enforcement operations target cybercrime rings involved in financial fraud, ATM cash-outs, and credential stuffing, while new regulations and partnerships aim to improve cybersecurity resilience across sectors.
Geopolitical Cyber Tensions Fuel Espionage and Military Operations
Jul 2, 2026Ongoing geopolitical conflicts involving Iran, DPRK, Russia, and Ukraine manifest in cyber espionage, sanctions enforcement, drone warfare, and cyber-physical attacks impacting civilian and military infrastructure.
Deepfake and AI-Generated Content Threats in Recent Fraud and Misinformation
Jul 1, 2026AI-generated deepfakes and digital impersonation are increasingly used in scams, voter manipulation, misinformation campaigns, and extremist radicalization, prompting legal and legislative responses.
Spike in state-linked cyber operations against critical infrastructure and government
Jun 30, 2026Multiple clusters describe espionage and disruption campaigns by nation-state actors against critical infrastructure, government, military, and political targets using malware, cyber-physical attacks, and stealth techniques.
Active exploitation of critical RCE and privilege escalation vulnerabilities
Jun 26, 2026Multiple critical vulnerabilities enabling remote code execution, privilege escalation, authentication bypass, and account hijacking in widely used software, developer tools, and open-source components are being actively exploited in the wild.
Cryptocurrency cybercrime spike: SIM swaps, bridge exploits, and laundering
Jun 26, 2026Organized cybercriminal groups and nation-state actors exploit SIM swap attacks, smart contract flaws, blockchain bridge vulnerabilities, and laundering schemes to steal crypto assets and evade sanctions.
Phishing campaigns exploiting AI and collaboration platform abuse
Jun 26, 2026Sophisticated phishing and social engineering campaigns use adversary-in-the-middle techniques, AI tools, multi-stage malware, and abuse of collaboration platforms like Microsoft 365 and Teams to bypass MFA and steal credentials across public, corporate, and government sectors.
Surge in AI-related attacks: prompt injection, deepfakes, and AI-enabled fraud
Jun 26, 2026New attack vectors exploit AI and LLM security tools via prompt injection, AI-generated deepfake fraud, voice cloning scams, AI-powered social engineering, and automated AI agents to conduct misinformation, harassment, and cyberattacks.
Ransomware campaigns exploit initial access brokers and novel malware vectors
Jun 30, 2026Recent ransomware activity increasingly involves initial access brokers, novel malware vectors like malicious browser extensions, and interconnected malware tool sharing among groups to maximize impact.
Major ransomware and cybercrime infrastructure takedowns disrupt criminal networks
Jun 25, 2026Law enforcement operations dismantle cybercrime-as-a-service platforms and ransomware groups exploiting enterprise and healthcare sectors, leveraging shared malware ecosystems.
Ransomware campaigns leveraging legitimate platforms and shared malware ecosystems
Jun 26, 2026Ransomware groups share malware tools and tactics, deploying loaders and infostealers, and increasingly abusing legitimate collaboration platforms for command-and-control communications to evade detection.
Malware campaigns spread loaders and RATs through popular platforms and social media
Jun 30, 2026Large-scale malware distribution campaigns use loaders and remote access trojans delivered through trusted platforms like Google Ads and WhatsApp to steal credentials and maintain persistence.
Spike in AI-powered cyberattacks and regulatory crackdowns
Jun 25, 2026Clusters cover AI-powered phishing, malware, deepfake misuse, agentic AI risks, and evolving government and corporate frameworks addressing AI security challenges.
Phishing and social engineering surge via collaboration tools and identity fraud
Jun 25, 2026Attackers use phishing, vishing, and impersonation tactics targeting Microsoft 365, government services, and enterprises to deliver malware and steal credentials.
Supply chain attacks hit open-source ecosystems and developer tools
Jun 26, 2026Attackers compromise open-source package repositories, CI/CD workflows, AI coding agents, and legacy contracts to inject malicious code, impacting thousands of users and decentralized finance platforms.
Supply Chain Attacks Targeting Open-Source Packages and Web Components
Jul 1, 2026Attackers compromise open-source package repositories and widely used web components to inject malicious code, enabling stealthy exploitation across development and production environments.
Cryptocurrency exploits and regulatory crackdowns escalate
Jun 25, 2026Clusters highlight attacks on DeFi platforms, exchanges, and wallets including clipboard hijacking and laundering takedowns, alongside governance and sanctions enforcement responses.