Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
27 topics
Active exploitation of critical RCE and privilege escalation zero-days in enterprise and open-source software
Oct 2, 2026Multiple clusters report urgent and active exploitation of critical remote code execution and privilege escalation vulnerabilities across widely used enterprise software, Linux distributions, and open-source libraries, including zero-days and rapid weaponization.
Drone and counter-drone operations in ongoing geopolitical conflicts
Oct 2, 2026Reports cover drone attacks on critical infrastructure, military drone deployments, counter-drone technologies, and related investments amid ongoing regional and maritime conflicts.
AI autonomous agents driving breaches and governance challenges
Oct 2, 2026Clusters describe AI-powered autonomous agents breaching government and healthcare systems, AI-driven cyberattacks, AI-enhanced phishing and scams, and the resulting regulatory and governance challenges.
State-linked espionage and cyber operations targeting governments and critical infrastructure
Oct 2, 2026Multiple clusters highlight espionage campaigns, state-sponsored cyberattacks, surveillance activities, arrests, and law enforcement responses targeting governments, academia, critical infrastructure, and journalists.
Critical zero-day exploits in enterprise network and security products
Oct 2, 2026Multiple clusters report zero-day and critical vulnerabilities in enterprise network devices, security products, and virtualization software being actively exploited to gain unauthorized access and disrupt defenses.
Geopolitical tensions fueling cyber, kinetic, and hybrid warfare including disinformation
Oct 2, 2026Clusters reveal cyberattacks, drone strikes, disinformation campaigns, sanctions, and military escalations linked to conflicts involving Russia, Ukraine, Iran, China, and other actors.
Ransomware and malware campaigns disrupting critical infrastructure and healthcare
Oct 2, 2026Ongoing ransomware and malware campaigns target critical infrastructure, healthcare, government, legal, transportation, and other sectors, often combining extortion, data leaks, and destructive tactics.
AI-enhanced phishing, social engineering, and BEC campaigns
Oct 2, 2026Multiple clusters describe phishing and social engineering attacks targeting healthcare, education, military, and AI sectors using AI-driven deepfakes, QR codes, OAuth flows, and impersonation scams.
Cryptocurrency theft and laundering exploiting privacy protocols and smart contracts
Oct 2, 2026Clusters report large-scale cryptocurrency thefts, laundering through privacy-enhanced protocols, smart contract exploits, and related social engineering scams targeting crypto platforms and wallets.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
629 topicsNo longer detected as trending. Sorted newest archived first.
Data breaches from credential theft and impersonation scams
Sep 17, 2026Recent data breaches have resulted from credential theft, impersonation scams, ransomware leaks, and vulnerabilities in third-party or internal systems, exposing large volumes of personal, corporate, and intelligence data across multiple sectors.
State-sponsored espionage targeting activists and critical sectors
Sep 17, 2026State-linked threat actors conduct sophisticated espionage operations targeting activists, journalists, dissidents, developers, and critical sectors, deploying spyware and leveraging zero-day exploits to advance geopolitical objectives.
State-sponsored espionage campaigns targeting activists and journalists
Sep 16, 2026Reports detail advanced state-sponsored spyware and cyber espionage operations surveilling dissidents, activists, journalists, and political opposition with zero-click and platform-level attacks.
Active exploitation of critical RCE and privilege escalation in enterprise and cloud software
Sep 16, 2026Clusters highlight critical RCE and privilege escalation flaws in enterprise, cloud, and Microsoft products actively exploited shortly after disclosure, demanding urgent patching.
Ransomware campaigns evolve with automation, data theft, and backup disruption
Sep 16, 2026Multiple ransomware groups continue to attack organizations globally across industries using automated extortion, data exfiltration, advanced malware, and targeting backup systems to maximize impact.
Active zero-day exploits in browsers and web platforms
Sep 17, 2026Active exploitation of zero-day and critical vulnerabilities has been reported in browsers (Chrome, Chromium), client software (curl, cPanel), and web/CMS platforms, enabling remote code execution and unauthorized access.
Phishing and MFA bypass campaigns leveraging advanced evasion techniques
Sep 16, 2026Multiple clusters report sophisticated phishing campaigns targeting consumers and enterprises using social engineering, session hijacking, OAuth abuse, MFA bypass, and browser-based deception.
Disruptive Cyberattacks on Critical Infrastructure and ICS
Sep 18, 2026Attackers increasingly target exposed industrial control systems, utilities, local governments, and critical infrastructure sectors causing operational disruptions and raising geopolitical concerns.
Evolving Ransomware Campaigns Targeting Multiple Sectors
Sep 15, 2026Multiple ransomware groups have targeted organizations across industries using phishing, identity theft, VPN/network exploits, and data extortion, with increasing focus on backup systems and critical infrastructure.
AI-Enhanced Phishing and Social Engineering Campaigns
Sep 15, 2026Clusters describe sophisticated phishing, vishing, and social engineering attacks using AI-driven methods, browser-in-the-browser, SMS scams, voice phishing, and targeting enterprise, education, and regional victims.
State-Linked Cyber Espionage and Sabotage Targeting Critical Infrastructure
Sep 15, 2026Government-authorized cyber operations include espionage campaigns, sabotage attempts on critical infrastructure, AI-driven surveillance of dissidents, and spyware targeting journalists and activists.
Ransomware Campaigns Evolve with New Tactics and Infrastructure Exploits
Sep 14, 2026Ransomware groups continue to target multiple industries including healthcare, public sector, technology, and critical infrastructure, leveraging phishing, identity exploits, VPN/network vulnerabilities, and new remote access trojans to disrupt operations and extort victims.
Active Zero-Day Exploits in Enterprise Software and Network Devices
Sep 14, 2026Multiple zero-day and critical vulnerabilities in widely used enterprise software and network devices are being actively exploited shortly after disclosure, impacting platforms like Citrix, Apache, and security products.
Recent Data Breaches Exploiting Third-Party and Internal Flaws
Sep 14, 2026Recent data breaches have compromised sensitive information across healthcare, government, consumer platforms, and service providers through exploitation of third-party and internal system vulnerabilities.
Cryptocurrency Protocol Exploits and Social Engineering Scams
Sep 14, 2026Cybercriminals exploit vulnerabilities in cryptocurrency protocols, decentralized finance platforms, and infrastructure, combined with phishing and social engineering campaigns targeting crypto users and wallets.
Active exploitation of zero-day and rapidly disclosed critical vulnerabilities
Sep 21, 2026Several zero-day and high-severity vulnerabilities in major software and platforms are actively exploited in the wild shortly after disclosure, prompting urgent patching and mitigation efforts.
September 2026’s record-breaking vulnerability disclosures and rapid exploit wave
Sep 22, 2026September 2026 saw an unprecedented volume of vulnerability disclosures and patch releases, with attackers rapidly exploiting critical flaws, pressuring organizations to accelerate patching efforts.
Critical RCE and Privilege Escalation Exploits in Linux and Open-Source
Sep 14, 2026Multiple critical vulnerabilities enabling remote code execution and privilege escalation have been disclosed and actively exploited across Linux distributions and open-source components, requiring urgent patching.
Data Breaches via Third-Party and Supply Chain Compromises
Sep 15, 2026Recent incidents involve attackers exploiting third-party providers, logistics, and supply chain partners to access and expose sensitive customer and organizational data.
Security incidents and misuse of AI models and platforms
Sep 13, 2026AI models such as Anthropic’s Claude and others have been exploited for cyber espionage, military uses, and unauthorized attacks, raising concerns about AI model security and governance.
Active critical RCE and privilege escalation vulnerabilities in Linux and open-source ecosystems
Sep 13, 2026Multiple Linux distributions and open-source projects have disclosed critical remote code execution and privilege escalation vulnerabilities, many actively exploited and requiring urgent patching.
Ransomware campaigns evolve with VPN exploits and multi-sector data theft
Sep 12, 2026Recent ransomware activity shows groups exploiting VPN vulnerabilities, combining data exfiltration with encryption, targeting healthcare, public institutions, and diverse industries while adopting advanced malware and recovery solutions.
Record critical vulnerabilities and active exploits hit Microsoft products
Sep 20, 2026Microsoft products saw record-breaking vulnerability disclosures and patching, with multiple critical authentication bypass, privilege escalation, and remote code execution flaws actively exploited.
Critical Linux and open-source vulnerabilities actively exploited this week
Sep 12, 2026Multiple clusters report critical remote code execution, privilege escalation, and denial-of-service vulnerabilities affecting major Linux distributions and open-source libraries, with active exploitation and urgent patching underway.