Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
26 topics
State-linked cyber espionage and hybrid warfare targeting critical sectors
Oct 1, 2026Clusters describe sophisticated state-sponsored cyber espionage, hybrid warfare activities, and cyberattacks targeting government, defense sectors, critical infrastructure, and geopolitical adversaries amid ongoing conflicts.
Active exploitation of critical RCE vulnerabilities across major software
Oct 1, 2026Multiple clusters report ongoing active exploitation of critical remote code execution (RCE) vulnerabilities across diverse widely used software platforms, including enterprise, infrastructure, and security tools, enabling attackers to execute arbitrary code remotely and escalate privileges.
Surge in AI-enabled social engineering, phishing, and deepfake scams
Oct 1, 2026Clusters highlight the growing use of AI-driven phishing, social engineering, and deepfake impersonations to defraud individuals and organizations, including financial institutions and crypto users, with emerging countermeasures.
Critical auth bypass vulnerabilities disclosed in open-source and industrial software
Oct 1, 2026Several critical authentication and authorization bypass flaws have been disclosed in open-source libraries, industrial control, and IoT devices, enabling unauthorized access, credential theft, and privilege escalation.
Cryptocurrency platform exploits and laundering via privacy coins
Oct 1, 2026Multiple incidents involve cryptocurrency exchange hacks, smart contract exploits, wallet thefts on various platforms including Apple devices, and laundering of stolen funds using privacy-focused coins.
Ransomware campaigns with combined encryption and data leak extortion
Oct 1, 2026Multiple ransomware groups continue to target organizations across industries and countries, combining encryption attacks with public data leak extortion tactics causing operational disruptions and financial losses.
Phishing and social engineering campaigns exploiting novel vectors and trusted platforms
Oct 1, 2026Threat actors increasingly use innovative phishing techniques leveraging holidays, homoglyph attacks, OAuth flows, QR codes, calendar invites, and trusted communication platforms to harvest credentials and deploy malware.
Security incidents from autonomous AI agents and prompt injection attacks
Oct 1, 2026Multiple incidents and clusters report security challenges from autonomous AI agents causing unauthorized data access, prompt injection attacks, and breaches of sensitive government, health, and enterprise systems.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
621 topicsNo longer detected as trending. Sorted newest archived first.
Ransomware campaigns targeting diverse sectors with advanced malware, data leaks, and evolving tactics
Sep 19, 2026Ransomware groups continue to target healthcare, critical infrastructure, government, manufacturing, education, and other sectors globally using sophisticated malware, data exfiltration, phishing, and negotiation strategies.
AI-enhanced phishing and social engineering targeting financial theft and credential compromise
Sep 19, 2026Phishing operations increasingly exploit AI-generated content, QR codes, voicemail and messaging platforms, OAuth flaws, and social engineering to steal credentials and crypto assets across sectors.
Phishing and Social Engineering Exploit AI, Voice, and Customer Support Channels This Week
Sep 23, 2026Phishing and social engineering attacks are evolving with AI-enabled deepfakes, voice phishing, SMS scams, QR code exploits, and fake customer support accounts targeting enterprise and consumer victims.
Critical web app framework and CMS vulnerabilities exploited this week
Sep 22, 2026High-risk flaws in WordPress, Grav CMS, XenForo, and other web platforms allow attackers to execute code remotely, bypass authentication, and hijack user sessions.
Deepfake and AI-generated content abuse for fraud, misinformation, and impersonation
Sep 19, 2026The rise of AI-generated deepfakes and synthetic media is fueling fraud, disinformation campaigns, and high-profile impersonations impacting elections, financial sectors, and public figures.
Nation-state and ransomware exploitation of zero-days for espionage and disruption
Sep 20, 2026State-linked and ransomware groups exploit zero-days and critical flaws to deploy backdoors, conduct espionage, and disrupt critical infrastructure and NGOs amid geopolitical tensions.
Active exploitation of critical RCE and privilege escalation vulnerabilities in enterprise and open-source software
Sep 19, 2026Multiple critical remote code execution and privilege escalation vulnerabilities affecting enterprise, Linux, and open-source software are being actively exploited, prompting urgent patching efforts.
Coordinated Ransomware Campaigns with Data Leaks and Novel Tactics
Sep 18, 2026Multiple ransomware groups have conducted coordinated attacks across industries and countries, leveraging automation, phishing, critical vulnerabilities, and novel malware strains to exfiltrate data, demand ransoms, and publicly expose victims.
Ransomware campaigns exploiting VPN, credential leaks, and third-party supply chain weaknesses
Sep 19, 2026Ransomware groups increasingly leverage leaked VPN credentials, third-party provider vulnerabilities, and supply chain weaknesses to gain initial access and escalate attacks.
State-sponsored espionage and surveillance leveraging AI, multi-platform exploit kits, and spyware targeting dissidents and critical infrastructure
Sep 19, 2026State actors from multiple countries conduct cyber espionage and surveillance using AI tools, exploit kits, and spyware campaigns targeting activists, government, military, and critical infrastructure.
State-Sponsored Espionage Targeting Tech Sectors and Activists
Sep 18, 2026State-aligned actors conduct cyber espionage campaigns targeting military technology, semiconductors, and deploy spyware against activists and dissidents, leveraging advanced exploit kits amid geopolitical tensions.
AI-driven deepfake and autonomous cyberattack surge
Sep 17, 2026AI technologies are increasingly used by threat actors to generate deepfakes for scams and disinformation, enhance social engineering and phishing campaigns, and conduct autonomous cyberattacks, reshaping the threat landscape with sophisticated and automated tactics.
Ransomware campaigns escalate with automation and evolving tactics
Sep 17, 2026Multiple ransomware groups have intensified attacks across industries worldwide, leveraging automation, exploiting critical vulnerabilities, third-party and supply-chain weaknesses, and evolving negotiation tactics to cause data leaks and operational disruptions.
Record-breaking patch releases amid active exploitation of critical Microsoft and Cisco vulnerabilities
Sep 19, 2026Microsoft and Cisco products face multiple critical vulnerabilities including zero-days and denial-of-service flaws that are actively exploited, accompanied by record-setting patch cycles.
Phishing campaigns exploiting MFA bypass and trusted platforms
Sep 17, 2026Phishing operations increasingly use AI-driven bots, MFA bypass techniques, voice and SMS channels, and trusted platforms like Microsoft 365 and Google to steal credentials and compromise enterprise and consumer accounts.
Rapid Zero-Day Exploitation and Critical Vulnerability Attacks
Sep 18, 2026Newly disclosed critical vulnerabilities in popular software and network devices are being rapidly exploited in the wild, including zero-day flaws prompting record-breaking patch releases and urgent security responses.
Data breaches from credential theft and impersonation scams
Sep 17, 2026Recent data breaches have resulted from credential theft, impersonation scams, ransomware leaks, and vulnerabilities in third-party or internal systems, exposing large volumes of personal, corporate, and intelligence data across multiple sectors.
State-sponsored espionage targeting activists and critical sectors
Sep 17, 2026State-linked threat actors conduct sophisticated espionage operations targeting activists, journalists, dissidents, developers, and critical sectors, deploying spyware and leveraging zero-day exploits to advance geopolitical objectives.
State-sponsored espionage campaigns targeting activists and journalists
Sep 16, 2026Reports detail advanced state-sponsored spyware and cyber espionage operations surveilling dissidents, activists, journalists, and political opposition with zero-click and platform-level attacks.
Active exploitation of critical RCE and privilege escalation in enterprise and cloud software
Sep 16, 2026Clusters highlight critical RCE and privilege escalation flaws in enterprise, cloud, and Microsoft products actively exploited shortly after disclosure, demanding urgent patching.
Ransomware campaigns evolve with automation, data theft, and backup disruption
Sep 16, 2026Multiple ransomware groups continue to attack organizations globally across industries using automated extortion, data exfiltration, advanced malware, and targeting backup systems to maximize impact.
Active zero-day exploits in browsers and web platforms
Sep 17, 2026Active exploitation of zero-day and critical vulnerabilities has been reported in browsers (Chrome, Chromium), client software (curl, cPanel), and web/CMS platforms, enabling remote code execution and unauthorized access.
Phishing and MFA bypass campaigns leveraging advanced evasion techniques
Sep 16, 2026Multiple clusters report sophisticated phishing campaigns targeting consumers and enterprises using social engineering, session hijacking, OAuth abuse, MFA bypass, and browser-based deception.
Disruptive Cyberattacks on Critical Infrastructure and ICS
Sep 18, 2026Attackers increasingly target exposed industrial control systems, utilities, local governments, and critical infrastructure sectors causing operational disruptions and raising geopolitical concerns.