Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
27 topics
Active exploitation of critical RCE and privilege escalation zero-days in enterprise and open-source software
Oct 2, 2026Multiple clusters report urgent and active exploitation of critical remote code execution and privilege escalation vulnerabilities across widely used enterprise software, Linux distributions, and open-source libraries, including zero-days and rapid weaponization.
Drone and counter-drone operations in ongoing geopolitical conflicts
Oct 2, 2026Reports cover drone attacks on critical infrastructure, military drone deployments, counter-drone technologies, and related investments amid ongoing regional and maritime conflicts.
AI autonomous agents driving breaches and governance challenges
Oct 2, 2026Clusters describe AI-powered autonomous agents breaching government and healthcare systems, AI-driven cyberattacks, AI-enhanced phishing and scams, and the resulting regulatory and governance challenges.
State-linked espionage and cyber operations targeting governments and critical infrastructure
Oct 2, 2026Multiple clusters highlight espionage campaigns, state-sponsored cyberattacks, surveillance activities, arrests, and law enforcement responses targeting governments, academia, critical infrastructure, and journalists.
Critical zero-day exploits in enterprise network and security products
Oct 2, 2026Multiple clusters report zero-day and critical vulnerabilities in enterprise network devices, security products, and virtualization software being actively exploited to gain unauthorized access and disrupt defenses.
Geopolitical tensions fueling cyber, kinetic, and hybrid warfare including disinformation
Oct 2, 2026Clusters reveal cyberattacks, drone strikes, disinformation campaigns, sanctions, and military escalations linked to conflicts involving Russia, Ukraine, Iran, China, and other actors.
Ransomware and malware campaigns disrupting critical infrastructure and healthcare
Oct 2, 2026Ongoing ransomware and malware campaigns target critical infrastructure, healthcare, government, legal, transportation, and other sectors, often combining extortion, data leaks, and destructive tactics.
AI-enhanced phishing, social engineering, and BEC campaigns
Oct 2, 2026Multiple clusters describe phishing and social engineering attacks targeting healthcare, education, military, and AI sectors using AI-driven deepfakes, QR codes, OAuth flows, and impersonation scams.
Cryptocurrency theft and laundering exploiting privacy protocols and smart contracts
Oct 2, 2026Clusters report large-scale cryptocurrency thefts, laundering through privacy-enhanced protocols, smart contract exploits, and related social engineering scams targeting crypto platforms and wallets.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
629 topicsNo longer detected as trending. Sorted newest archived first.
Active Exploitation of Critical RCE Vulnerabilities in Enterprise and Open-Source Software
Sep 9, 2026Multiple clusters report critical remote code execution (RCE) vulnerabilities across Linux distributions, enterprise platforms, and open-source software that are currently under active exploitation by threat actors.
Exploitation of web application and Node.js vulnerabilities for unauthorized access
Sep 8, 2026Attackers actively exploit critical vulnerabilities in web platforms, CMSs, and Node.js runtimes to execute remote code, hijack sessions, and steal credentials.
Large-scale data breaches exposing personal and employee information
Sep 11, 2026Clusters describe significant data breaches involving millions of records caused by unauthorized API access, internal system exploitation, and credential theft across media, healthcare, government, and consumer platforms.
Phishing and social engineering campaigns enabling ransomware, credential theft, and MFA bypass
Sep 8, 2026Widespread phishing and social engineering operations leverage automation, voice phishing, trusted platforms, and advanced evasion techniques to deliver ransomware, steal credentials, bypass MFA, and compromise enterprise and targeted sectors.
Active exploitation of critical RCE vulnerabilities in Linux and open-source ecosystems
Sep 8, 2026Multiple critical remote code execution and privilege escalation vulnerabilities have been disclosed and actively exploited across Linux distributions, open-source software, and network infrastructure, prompting urgent patching efforts.
Cyberattacks disrupting public sector and critical infrastructure operations this week
Sep 10, 2026Multiple cyber incidents impact water utilities, local governments, schools, law firms, and critical infrastructure sectors causing operational disruptions and highlighting the need for enhanced protection and legislative measures.
AI-powered phishing targeting high-value credentials
Sep 7, 2026Phishing and social engineering campaigns increasingly use AI-generated content, voice phishing, brand impersonation, and targeted tactics to compromise high-value users, bypass MFA, and steal financial, corporate, and government credentials.
Cyberattacks disrupting critical infrastructure and public sector services this week
Sep 7, 2026Recent cyber operations, including ransomware and AI-powered attacks, have caused outages and operational impacts across critical infrastructure sectors such as energy, water, manufacturing, and government services.
Critical infrastructure and power grid cyber disruptions amid geopolitical tensions
Sep 6, 2026Cyber operations cause operational disruptions in power grids, manufacturing, healthcare, and other critical infrastructure sectors amid geopolitical tensions and national security initiatives.
Critical Linux and open-source vulnerabilities actively exploited this week
Sep 6, 2026Multiple critical security flaws affecting Linux distributions and core open-source system components have been disclosed and actively exploited, prompting urgent patching efforts.
Cyberattacks disrupting critical infrastructure and essential public services
Sep 11, 2026Reports detail cyberattacks causing outages and risks in water utilities, local governments, schools, energy, and other essential infrastructure sectors, including lessons from nation-state operations.
Surge in AI-driven autonomous cyberattacks and prompt injection exploits
Sep 7, 2026Emerging AI-powered cyber threats encompass autonomous AI agents conducting full kill chains, prompt injection attacks, AI malware frameworks, botnets leveraging LLMs, and AI model poisoning, alongside new AI-enabled defense platforms.
Critical RCE vulnerabilities actively exploited in Linux and open-source software
Sep 7, 2026Multiple critical RCE vulnerabilities affecting Linux distributions, open-source libraries, and widely used software components have been disclosed, patched, and actively exploited, including kernel, system tools, and cloud plugins.
Active exploitation of critical RCE and zero-day vulnerabilities this week
Sep 5, 2026Clusters report multiple critical RCE and zero-day vulnerabilities in browsers, open-source projects, enterprise software, network devices, and industrial platforms actively exploited in the wild.
Advanced phishing and social engineering campaigns with new evasion tactics
Sep 5, 2026Multiple campaigns use evolving phishing, vishing, fake recruiters, MFA bypass, impersonation, and social engineering tactics to steal credentials from individuals, corporations, governments, and public sectors.
Nation-state espionage and insider-assisted malware campaigns this week
Sep 6, 2026State-sponsored actors conduct advanced malware and espionage operations against developers, government, critical infrastructure, and use fake identities and insider recruitment for infiltration.
Advanced spyware campaigns targeting activists and political groups
Sep 12, 2026Sophisticated spyware campaigns focus on activists, opposition figures, and critical government and infrastructure targets, with nation-state actors conducting espionage and insider threats.
Emerging malware with unconventional C2 and disguised apps this week
Sep 6, 2026New malware strains employ innovative C2 methods via messaging platforms and fake or disguised apps to evade detection and target diverse user bases including developers and consumers.
Ransomware campaigns hitting government and public sectors, disrupting backups
Sep 5, 2026Ransomware groups increasingly focus on government agencies, municipal entities, and critical infrastructure, often disrupting backup systems and leveraging identity theft and social engineering.
Law enforcement takedowns of cyber fraud and phishing operations
Sep 13, 2026Coordinated law enforcement actions have disrupted cyber fraud rings and phishing campaigns across multiple regions, resulting in arrests and infrastructure takedowns.
Large-scale exploits and phishing targeting cryptocurrency and DeFi platforms
Sep 7, 2026Multiple incidents involve large-scale thefts, DDoS attacks, and customized phishing campaigns targeting cryptocurrency exchanges, DeFi lending platforms, and crypto users via platform-specific scams.
Major botnet takedown through international law enforcement cooperation
Sep 11, 2026The dismantling of a long-standing botnet through multinational collaboration marks a significant milestone in disrupting cybercrime infrastructure.
Ransomware campaigns evolve with backup disruption and credential theft tactics
Sep 7, 2026Ransomware groups are adopting new command-and-control frameworks, targeting backup systems to hinder recovery, and leveraging identity theft and social engineering to disrupt diverse sectors including public services and education.
Critical Linux and open-source vulnerabilities actively exploited this week
Sep 4, 2026Multiple critical vulnerabilities affecting Linux kernels, distributions, and open-source libraries have been disclosed with active exploitation observed, requiring urgent patching.