Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
27 topics
Active exploitation of critical RCE and privilege escalation zero-days in enterprise and open-source software
Oct 2, 2026Multiple clusters report urgent and active exploitation of critical remote code execution and privilege escalation vulnerabilities across widely used enterprise software, Linux distributions, and open-source libraries, including zero-days and rapid weaponization.
Drone and counter-drone operations in ongoing geopolitical conflicts
Oct 2, 2026Reports cover drone attacks on critical infrastructure, military drone deployments, counter-drone technologies, and related investments amid ongoing regional and maritime conflicts.
AI autonomous agents driving breaches and governance challenges
Oct 2, 2026Clusters describe AI-powered autonomous agents breaching government and healthcare systems, AI-driven cyberattacks, AI-enhanced phishing and scams, and the resulting regulatory and governance challenges.
State-linked espionage and cyber operations targeting governments and critical infrastructure
Oct 2, 2026Multiple clusters highlight espionage campaigns, state-sponsored cyberattacks, surveillance activities, arrests, and law enforcement responses targeting governments, academia, critical infrastructure, and journalists.
Critical zero-day exploits in enterprise network and security products
Oct 2, 2026Multiple clusters report zero-day and critical vulnerabilities in enterprise network devices, security products, and virtualization software being actively exploited to gain unauthorized access and disrupt defenses.
Geopolitical tensions fueling cyber, kinetic, and hybrid warfare including disinformation
Oct 2, 2026Clusters reveal cyberattacks, drone strikes, disinformation campaigns, sanctions, and military escalations linked to conflicts involving Russia, Ukraine, Iran, China, and other actors.
Ransomware and malware campaigns disrupting critical infrastructure and healthcare
Oct 2, 2026Ongoing ransomware and malware campaigns target critical infrastructure, healthcare, government, legal, transportation, and other sectors, often combining extortion, data leaks, and destructive tactics.
AI-enhanced phishing, social engineering, and BEC campaigns
Oct 2, 2026Multiple clusters describe phishing and social engineering attacks targeting healthcare, education, military, and AI sectors using AI-driven deepfakes, QR codes, OAuth flows, and impersonation scams.
Cryptocurrency theft and laundering exploiting privacy protocols and smart contracts
Oct 2, 2026Clusters report large-scale cryptocurrency thefts, laundering through privacy-enhanced protocols, smart contract exploits, and related social engineering scams targeting crypto platforms and wallets.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
629 topicsNo longer detected as trending. Sorted newest archived first.
Critical RCE vulnerabilities actively exploited in enterprise and cloud software
Sep 12, 2026Several clusters detail critical RCE vulnerabilities in enterprise, cloud, and open-source software platforms including Microsoft products, developer tools, and network devices, with active exploitation by threat actors.
Exploitation and patching of critical vulnerabilities in developer and cloud platforms
Sep 13, 2026Critical vulnerabilities in developer tools and cloud platforms like GitLab, Okta, Microsoft SQL Server, and Azure have been actively exploited or rapidly patched.
Ransomware campaigns disrupting critical infrastructure and public sector
Sep 11, 2026Clusters cover ransomware campaigns focusing on negotiation tactics, backup and recovery weaknesses, identity-based access exploits, novel command-and-control frameworks, and attacks disrupting critical infrastructure, public services, and education.
Multi-million dollar cryptocurrency platform exploits and DeFi thefts
Sep 12, 2026DeFi and blockchain platforms suffer large-scale token thefts, network halts, and fraud through vulnerabilities, price manipulation, and malware targeting crypto infrastructure and users.
Emerging AI Prompt Injection and LLM Security Bypass Attacks
Sep 14, 2026New attack methods exploit large language models through covert prompt injection and AI model security breaches, posing novel risks to AI-powered applications.
Surge in AI-driven autonomous cyberattacks and defenses
Sep 11, 2026Clusters highlight AI-powered attacks including autonomous AI agents conducting cyber intrusions, AI-enhanced phishing and social engineering, AI-driven ransomware, and AI-enabled cybersecurity tools and vulnerabilities.
AI-enhanced phishing and social engineering campaigns targeting multiple sectors
Sep 11, 2026Multiple clusters describe evolving phishing and social engineering attacks enhanced by AI, targeting sectors including education, cryptocurrency users, enterprises, and executives via email, voice phishing, and session hijacking.
AI-Driven Phishing and Social Engineering Campaigns Escalate
Sep 14, 2026Phishing and social engineering attacks increasingly use AI-driven techniques, voice phishing, automation, MFA bypass, and sophisticated lures targeting sectors such as education, cryptocurrency users, executives, and enterprise cloud services.
Advanced phishing and social engineering targeting enterprise SaaS and cloud users
Sep 13, 2026Sophisticated phishing and social engineering attacks increasingly exploit MFA bypass, vishing, session hijacking, and impersonation to compromise Microsoft 365, cloud services, and enterprise SaaS accounts.
Advanced phishing and social engineering targeting cloud and enterprise users
Sep 12, 2026Multiple campaigns use sophisticated phishing, vishing, MFA bypass, OAuth abuse, and social engineering techniques to compromise Microsoft 365, government, public sector, and hardware wallet users.
Critical web and cloud platform token exploitation vulnerabilities
Sep 11, 2026Clusters reveal critical flaws in web and cloud platforms including OAuth and token management vulnerabilities, enabling unauthorized access, credential theft, and token minting.
State-sponsored espionage targeting government, military, and critical infrastructure
Sep 11, 2026Clusters highlight espionage activities by nation-state and state-linked actors using exploit kits, fraudulent identities, SIM supply chain infiltration, and advanced tactics against government, military, and critical infrastructure sectors.
Surge in AI-powered autonomous cyberattacks and AI-driven exploit discovery
Sep 10, 2026Clusters highlight AI agents autonomously conducting cyber intrusions, accelerating vulnerability discovery and exploitation, and enabling new attack vectors including prompt injection and malware delivery, complicating defense and remediation efforts.
Active zero-day exploitation campaigns deploying advanced malware
Sep 10, 2026Threat actors are actively exploiting zero-day and critical vulnerabilities in widely used software and security products to deploy advanced malware and post-exploitation frameworks, prompting urgent patching and alerts.
Ransomware campaigns leveraging identity exploitation, novel C2 frameworks, and targeting critical infrastructure and healthcare
Sep 10, 2026Ransomware groups continue evolving tactics by exploiting identity and access vectors, deploying new command-and-control frameworks, focusing on healthcare, public sector, education, and critical infrastructure, and increasingly targeting backup and recovery systems.
Microsoft’s record vulnerability patching amid active zero-day exploits
Sep 17, 2026Microsoft has released unprecedented large-scale patches addressing nearly 1,000 vulnerabilities, including multiple zero-days actively exploited in the wild, reflecting a record-breaking vulnerability management effort.
September 2026 Microsoft patch surge amid active zero-day exploitation
Sep 13, 2026Microsoft released an unprecedented volume of patches in September 2026 addressing hundreds of vulnerabilities, including multiple actively exploited zero-days affecting Windows and enterprise software.
Ransomware Campaigns Escalate Attacks on Critical Infrastructure and Healthcare
Sep 9, 2026Ransomware groups are intensifying attacks with fragmentation, refined negotiation strategies, and targeting of healthcare, critical infrastructure, municipal, government, and SMB sectors, often leveraging phishing and identity-based access.
Record Windows Critical Vulnerabilities and Exploits This Week
Sep 14, 2026Numerous critical vulnerabilities including local privilege escalation and remote code execution flaws have been disclosed and patched in Microsoft Windows components, with record-breaking patch releases and active exploitation.
Microsoft’s Record-Breaking September 2026 Vulnerability Disclosures and Exploits
Sep 15, 2026Microsoft's September 2026 Patch Tuesday addressed nearly 1,000 vulnerabilities, including multiple critical and zero-day flaws with active exploitation observed.
Record-breaking Windows vulnerabilities and patch releases amid active exploits
Sep 21, 2026Critical Windows vulnerabilities, privilege escalations, and record-breaking patch releases addressing active exploits have been reported.
Advanced Phishing and Social Engineering Campaigns Employing Evasion Techniques
Sep 9, 2026Phishing and social engineering attacks increasingly leverage advanced evasion techniques, MFA bypass, vishing, session hijacking, and trusted platforms to compromise enterprise, education, government, and financial accounts.
New data breaches via unauthorized access and third-party logistics
Sep 10, 2026Multiple incidents involve large-scale data breaches caused by unauthorized API access, web vulnerabilities, and supply chain compromises impacting healthcare, logistics, and other sectors.
Ransomware campaigns targeting backup systems and diverse sectors
Sep 8, 2026Ransomware groups continue to impact government, financial, healthcare, SMBs, and public sectors, increasingly focusing on backup infrastructure disruption and using novel command-and-control frameworks.