Skip to content

Smart Topics

Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.

Live Smart Topics

26 topics
State-linked cyber espionage and hybrid warfare targeting critical sectors
Live

State-linked cyber espionage and hybrid warfare targeting critical sectors

Oct 1, 2026

Clusters describe sophisticated state-sponsored cyber espionage, hybrid warfare activities, and cyberattacks targeting government, defense sectors, critical infrastructure, and geopolitical adversaries amid ongoing conflicts.

www.nas.gov.uaAljazeeraCyberscoopBbcNpr236 sources 59 clusters
Active exploitation of critical RCE vulnerabilities across major software
Live

Active exploitation of critical RCE vulnerabilities across major software

Oct 1, 2026

Multiple clusters report ongoing active exploitation of critical remote code execution (RCE) vulnerabilities across diverse widely used software platforms, including enterprise, infrastructure, and security tools, enabling attackers to execute arbitrary code remotely and escalate privileges.

EndorlabsHelpnetsecurityLinuxsecuritycve.mitre.orgexploitbulletin.com247 sources 123 clusters
Surge in AI-enabled social engineering, phishing, and deepfake scams
Live

Surge in AI-enabled social engineering, phishing, and deepfake scams

Oct 1, 2026

Clusters highlight the growing use of AI-driven phishing, social engineering, and deepfake impersonations to defraud individuals and organizations, including financial institutions and crypto users, with emerging countermeasures.

www.politico.comItproTechcrunchBriefs.CoBmjgroup346 sources 79 clusters
Critical auth bypass vulnerabilities disclosed in open-source and industrial software
Live

Critical auth bypass vulnerabilities disclosed in open-source and industrial software

Oct 1, 2026

Several critical authentication and authorization bypass flaws have been disclosed in open-source libraries, industrial control, and IoT devices, enabling unauthorized access, credential theft, and privilege escalation.

psirt.watchguard.comSecurityweekTechgigFeeds.4Sysopswww.cve.org49 sources 27 clusters
Cryptocurrency platform exploits and laundering via privacy coins
Live

Cryptocurrency platform exploits and laundering via privacy coins

Oct 1, 2026

Multiple incidents involve cryptocurrency exchange hacks, smart contract exploits, wallet thefts on various platforms including Apple devices, and laundering of stolen funds using privacy-focused coins.

MirrorTrendingtopics.EuCryptotickerct.comSaudigazette.Sa178 sources 42 clusters
Ransomware campaigns with combined encryption and data leak extortion
Live

Ransomware campaigns with combined encryption and data leak extortion

Oct 1, 2026

Multiple ransomware groups continue to target organizations across industries and countries, combining encryption attacks with public data leak extortion tactics causing operational disruptions and financial losses.

Ransomware.Livewww.insurancebusinessmag.comwww.breachsense.comRedpacketsecurityTechcrunch201 sources 59 clusters
Phishing and social engineering campaigns exploiting novel vectors and trusted platforms
Live

Phishing and social engineering campaigns exploiting novel vectors and trusted platforms

Oct 1, 2026

Threat actors increasingly use innovative phishing techniques leveraging holidays, homoglyph attacks, OAuth flows, QR codes, calendar invites, and trusted communication platforms to harvest credentials and deploy malware.

SecurityweekCybernewswww.cleafy.comCrypto-EconomyCyberinsider115 sources 24 clusters
Security incidents from autonomous AI agents and prompt injection attacks
Live

Security incidents from autonomous AI agents and prompt injection attacks

Oct 1, 2026

Multiple incidents and clusters report security challenges from autonomous AI agents causing unauthorized data access, prompt injection attacks, and breaches of sensitive government, health, and enterprise systems.

Asiae.Co.KrTrendingtopics.Euwww.canberratimes.com.auTheguardiandeveloper.nvidia.com265 sources 68 clusters
Russian energy sector targeting and threats
Broad

Russian energy sector targeting and threats

May 29, 2026

Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.

Kyivpostwww.cnn.comBusinessinsiderThehill112.Ua324 sources 48 clusters
Russian government targeting government sectors
Trending

Russian government targeting government sectors

May 29, 2026

Cyber activities by Russian state actors aimed at government entities across various regions and sectors.

En.Ara.CatPetriwww.reuters.comwww.cnn.comThehackernews339 sources 32 clusters
Iranian DDoS activity targeting regional services
Live

Iranian DDoS activity targeting regional services

May 29, 2026

This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.

DarkreadingFeeds2.FeedburnerCloudsekPrnewswireIndustrialcyber.Co149 sources 8 clusters
German government targeting cyber threat actors
Broad

German government targeting cyber threat actors

May 29, 2026

Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.

En.Ara.CatEinpresswirewww.reuters.comThehackernewsSecurityaffairs.Co136 sources 14 clusters
Canadian energy sector targeted by cyber threats
Live

Canadian energy sector targeted by cyber threats

May 29, 2026

Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.

Aninews.InBusinessinsiderLightreadingHeise.DeSg.Finance.Yahoo96 sources 11 clusters
Iranian actors targeting energy infrastructure
Broad

Iranian actors targeting energy infrastructure

May 29, 2026

Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.

www.cnn.comBusinessinsiderwww.gov.ukThehillapnews.com292 sources 41 clusters
Chinese government targeting international research institutions
Broad

Chinese government targeting international research institutions

May 29, 2026

Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.

En.Ara.CatPetriEinpresswirewww.reuters.comwww.cnn.com338 sources 33 clusters
Chinese financial sector targeting and defense activities
Broad

Chinese financial sector targeting and defense activities

May 29, 2026

Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.

En.Ara.CatEinpresswirewww.reuters.comRss.SlashdotIconnect007367 sources 27 clusters
North Korean Lazarus Group targeting cryptocurrency platforms
Live

North Korean Lazarus Group targeting cryptocurrency platforms

May 29, 2026

Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.

Mexc.CoBitgetTheblock.Colayerzero.networkCryptopolitan93 sources 21 clusters
Indian government targeting digital infrastructure
Broad

Indian government targeting digital infrastructure

May 29, 2026

Cyber threat activities by actors targeting India's government digital infrastructure and online services.

Einpresswirewww.cnn.comTribuneindiaSecurityaffairs.CoMillenniumpost.In176 sources 18 clusters
Chinese transportation sector cyber activities
Live

Chinese transportation sector cyber activities

May 29, 2026

Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.

DarkreadingFeeds2.FeedburnerCloudsekPrnewswireapnews.com160 sources 12 clusters
Canadian financial sector targeted by cyber threats
Broad

Canadian financial sector targeted by cyber threats

May 29, 2026

Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.

En.Ara.Catwww.reuters.comSecurityaffairs.CoDarkreadingFeeds2.Feedburner206 sources 11 clusters
Indian healthcare sector targeted by cyber threat actors
Live

Indian healthcare sector targeted by cyber threat actors

May 29, 2026

Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.

Aninews.InEinpresswirewww.cnn.comSecurityaffairs.CoM.Economictimes104 sources 11 clusters
Russian DDoS activity targeting infrastructure
Live

Russian DDoS activity targeting infrastructure

May 29, 2026

Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.

ThehackernewsCybersecuritynewsDarkreadingFeeds2.FeedburnerCryptobriefing165 sources 8 clusters
Indian financial sector cybersecurity activity
New

Indian financial sector cybersecurity activity

May 29, 2026

Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.

LbcSmestreet.InEtvbharatwww.reuters.comMondaq79 sources 6 clusters
German supply chain actors targeted by malicious packages
Broad

German supply chain actors targeted by malicious packages

May 29, 2026

Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.

En.Ara.CatDigital.Nhs.Ukwww.reuters.comCsoonlineThehackernews367 sources 10 clusters
German financial sector targeted by cyber threat actors
Broad

German financial sector targeted by cyber threat actors

May 29, 2026

Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.

En.Ara.CatDigital.Nhs.UkEinpresswirewww.reuters.comSonatype370 sources 13 clusters
TeamPCP supply chain activity
Broad

TeamPCP supply chain activity

May 29, 2026

Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.

Digital.Nhs.UkTechcrunchAppleinsiderItnews.AuTechnadu313 sources 8 clusters

Archived Smart Topics

621 topics

No longer detected as trending. Sorted newest archived first.

Ransomware campaigns targeting diverse sectors with advanced malware, data leaks, and evolving tactics
Archived

Ransomware campaigns targeting diverse sectors with advanced malware, data leaks, and evolving tactics

Sep 19, 2026

Ransomware groups continue to target healthcare, critical infrastructure, government, manufacturing, education, and other sectors globally using sophisticated malware, data exfiltration, phishing, and negotiation strategies.

teknologi.idDexposeUnit42.PaloaltonetworksRansomware.LiveRedpacketsecurity282 sources 105 clusters
AI-enhanced phishing and social engineering targeting financial theft and credential compromise
Archived

AI-enhanced phishing and social engineering targeting financial theft and credential compromise

Sep 19, 2026

Phishing operations increasingly exploit AI-generated content, QR codes, voicemail and messaging platforms, OAuth flaws, and social engineering to steal credentials and crypto assets across sectors.

1password.comCrypto.NewsArstechnicaThehackernewsAbc7Ny263 sources 49 clusters
Phishing and Social Engineering Exploit AI, Voice, and Customer Support Channels This Week
Archived

Phishing and Social Engineering Exploit AI, Voice, and Customer Support Channels This Week

Sep 23, 2026

Phishing and social engineering attacks are evolving with AI-enabled deepfakes, voice phishing, SMS scams, QR code exploits, and fake customer support accounts targeting enterprise and consumer victims.

BleepingcomputerCrypto.NewsMediapostCybernewswww.cleafy.com110 sources 24 clusters
Critical web app framework and CMS vulnerabilities exploited this week
Archived

Critical web app framework and CMS vulnerabilities exploited this week

Sep 22, 2026

High-risk flaws in WordPress, Grav CMS, XenForo, and other web platforms allow attackers to execute code remotely, bypass authentication, and hijack user sessions.

FieldeffectBleepingcomputerSecurityweekSploituswww.vulncheck.com41 sources 19 clusters
Deepfake and AI-generated content abuse for fraud, misinformation, and impersonation
Archived

Deepfake and AI-generated content abuse for fraud, misinformation, and impersonation

Sep 19, 2026

The rise of AI-generated deepfakes and synthetic media is fueling fraud, disinformation campaigns, and high-profile impersonations impacting elections, financial sectors, and public figures.

AxiosTimesofindia.IndiatimesNews.Bloomberglawwww.in.grNews.Ycombinator180 sources 29 clusters
Nation-state and ransomware exploitation of zero-days for espionage and disruption
Archived

Nation-state and ransomware exploitation of zero-days for espionage and disruption

Sep 20, 2026

State-linked and ransomware groups exploit zero-days and critical flaws to deploy backdoors, conduct espionage, and disrupt critical infrastructure and NGOs amid geopolitical tensions.

AljazeeraBbcSpectrumlocalnewswww.microsoft.comShelter.In.Ua119 sources 16 clusters
Active exploitation of critical RCE and privilege escalation vulnerabilities in enterprise and open-source software
Archived

Active exploitation of critical RCE and privilege escalation vulnerabilities in enterprise and open-source software

Sep 19, 2026

Multiple critical remote code execution and privilege escalation vulnerabilities affecting enterprise, Linux, and open-source software are being actively exploited, prompting urgent patching efforts.

Api.Msrc.MicrosoftLinuxsecuritywww.cve.orgWordfencecve.mitre.org186 sources 105 clusters
Coordinated Ransomware Campaigns with Data Leaks and Novel Tactics
Archived

Coordinated Ransomware Campaigns with Data Leaks and Novel Tactics

Sep 18, 2026

Multiple ransomware groups have conducted coordinated attacks across industries and countries, leveraging automation, phishing, critical vulnerabilities, and novel malware strains to exfiltrate data, demand ransoms, and publicly expose victims.

teknologi.idDexposeRansomware.LiveRedpacketsecuritywww.insurancebusinessmag.com264 sources 98 clusters
Ransomware campaigns exploiting VPN, credential leaks, and third-party supply chain weaknesses
Archived

Ransomware campaigns exploiting VPN, credential leaks, and third-party supply chain weaknesses

Sep 19, 2026

Ransomware groups increasingly leverage leaked VPN credentials, third-party provider vulnerabilities, and supply chain weaknesses to gain initial access and escalate attacks.

Ground.NewsRansomware.Livewww.techtarget.comXAsec.Ahnlab26 sources 12 clusters
State-sponsored espionage and surveillance leveraging AI, multi-platform exploit kits, and spyware targeting dissidents and critical infrastructure
Archived

State-sponsored espionage and surveillance leveraging AI, multi-platform exploit kits, and spyware targeting dissidents and critical infrastructure

Sep 19, 2026

State actors from multiple countries conduct cyber espionage and surveillance using AI tools, exploit kits, and spyware campaigns targeting activists, government, military, and critical infrastructure.

Biz.LigaNationaltechnologyInfosecurity-Magazineopenai.comFinance.Biggo217 sources 20 clusters
State-Sponsored Espionage Targeting Tech Sectors and Activists
Archived

State-Sponsored Espionage Targeting Tech Sectors and Activists

Sep 18, 2026

State-aligned actors conduct cyber espionage campaigns targeting military technology, semiconductors, and deploy spyware against activists and dissidents, leveraging advanced exploit kits amid geopolitical tensions.

NationaltechnologyInfosecurity-MagazineFinance.BiggoMlexEutoday189 sources 16 clusters
AI-driven deepfake and autonomous cyberattack surge
Archived

AI-driven deepfake and autonomous cyberattack surge

Sep 17, 2026

AI technologies are increasingly used by threat actors to generate deepfakes for scams and disinformation, enhance social engineering and phishing campaigns, and conduct autonomous cyberattacks, reshaping the threat landscape with sophisticated and automated tactics.

Biz.LigaUa.NewsAxioswww.reuters.comCyfirma723 sources 121 clusters
Ransomware campaigns escalate with automation and evolving tactics
Archived

Ransomware campaigns escalate with automation and evolving tactics

Sep 17, 2026

Multiple ransomware groups have intensified attacks across industries worldwide, leveraging automation, exploiting critical vulnerabilities, third-party and supply-chain weaknesses, and evolving negotiation tactics to cause data leaks and operational disruptions.

RedpacketsecurityDexposeRansomware.LiveDailymaverick.Co.ZaEnergate-Messenger264 sources 84 clusters
Record-breaking patch releases amid active exploitation of critical Microsoft and Cisco vulnerabilities
Archived

Record-breaking patch releases amid active exploitation of critical Microsoft and Cisco vulnerabilities

Sep 19, 2026

Microsoft and Cisco products face multiple critical vulnerabilities including zero-days and denial-of-service flaws that are actively exploited, accompanied by record-setting patch cycles.

Api.Msrc.Microsoftwww.cve.orgcwe.mitre.orgvulnfeed.itRedpacketsecurity133 sources 29 clusters
Phishing campaigns exploiting MFA bypass and trusted platforms
Archived

Phishing campaigns exploiting MFA bypass and trusted platforms

Sep 17, 2026

Phishing operations increasingly use AI-driven bots, MFA bypass techniques, voice and SMS channels, and trusted platforms like Microsoft 365 and Google to steal credentials and compromise enterprise and consumer accounts.

1password.comArstechnicaEnglish.Kyodonewswww.fortra.comSocprime243 sources 33 clusters
Rapid Zero-Day Exploitation and Critical Vulnerability Attacks
Archived

Rapid Zero-Day Exploitation and Critical Vulnerability Attacks

Sep 18, 2026

Newly disclosed critical vulnerabilities in popular software and network devices are being rapidly exploited in the wild, including zero-day flaws prompting record-breaking patch releases and urgent security responses.

vulnfeed.itCryptoranknvd.nist.govForkast.Newsexploitbulletin.com73 sources 18 clusters
Data breaches from credential theft and impersonation scams
Archived

Data breaches from credential theft and impersonation scams

Sep 17, 2026

Recent data breaches have resulted from credential theft, impersonation scams, ransomware leaks, and vulnerabilities in third-party or internal systems, exposing large volumes of personal, corporate, and intelligence data across multiple sectors.

CybersecuritynewsResearch.CheckpointInternationalcyberdigestShatteredForklog152 sources 20 clusters
State-sponsored espionage targeting activists and critical sectors
Archived

State-sponsored espionage targeting activists and critical sectors

Sep 17, 2026

State-linked threat actors conduct sophisticated espionage operations targeting activists, journalists, dissidents, developers, and critical sectors, deploying spyware and leveraging zero-day exploits to advance geopolitical objectives.

Nationaltechnologywww.gadgetreview.comFinance.BiggoEutodayCybersecurity-Insiders151 sources 25 clusters
State-sponsored espionage campaigns targeting activists and journalists
Archived

State-sponsored espionage campaigns targeting activists and journalists

Sep 16, 2026

Reports detail advanced state-sponsored spyware and cyber espionage operations surveilling dissidents, activists, journalists, and political opposition with zero-click and platform-level attacks.

NationaltechnologyN1Info.RsArstechnicaEnglish.KyodonewsCybersecurity-Insiders326 sources 20 clusters
Active exploitation of critical RCE and privilege escalation in enterprise and cloud software
Archived

Active exploitation of critical RCE and privilege escalation in enterprise and cloud software

Sep 16, 2026

Clusters highlight critical RCE and privilege escalation flaws in enterprise, cloud, and Microsoft products actively exploited shortly after disclosure, demanding urgent patching.

Api.Msrc.Microsoftwww.cve.orgcwe.mitre.orgLinuxsecurityScworld311 sources 124 clusters
Ransomware campaigns evolve with automation, data theft, and backup disruption
Archived

Ransomware campaigns evolve with automation, data theft, and backup disruption

Sep 16, 2026

Multiple ransomware groups continue to attack organizations globally across industries using automated extortion, data exfiltration, advanced malware, and targeting backup systems to maximize impact.

teknologi.idRedpacketsecurityDexposeRansomware.LiveCybersecuritynews323 sources 87 clusters
Active zero-day exploits in browsers and web platforms
Archived

Active zero-day exploits in browsers and web platforms

Sep 17, 2026

Active exploitation of zero-day and critical vulnerabilities has been reported in browsers (Chrome, Chromium), client software (curl, cPanel), and web/CMS platforms, enabling remote code execution and unauthorized access.

LinuxsecurityMothership.Sgcve.mitre.orgMediumEsecurityplanet78 sources 17 clusters
Phishing and MFA bypass campaigns leveraging advanced evasion techniques
Archived

Phishing and MFA bypass campaigns leveraging advanced evasion techniques

Sep 16, 2026

Multiple clusters report sophisticated phishing campaigns targeting consumers and enterprises using social engineering, session hijacking, OAuth abuse, MFA bypass, and browser-based deception.

ArstechnicaEnglish.KyodonewsFstechwww.fortra.comSocprime342 sources 55 clusters
Disruptive Cyberattacks on Critical Infrastructure and ICS
Archived

Disruptive Cyberattacks on Critical Infrastructure and ICS

Sep 18, 2026

Attackers increasingly target exposed industrial control systems, utilities, local governments, and critical infrastructure sectors causing operational disruptions and raising geopolitical concerns.

Amp.ScmpFtItweb.Co.Zawww.rockwellautomation.comdispel.com45 sources 13 clusters