Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
27 topics
Active exploitation of critical RCE and privilege escalation zero-days in enterprise and open-source software
Oct 2, 2026Multiple clusters report urgent and active exploitation of critical remote code execution and privilege escalation vulnerabilities across widely used enterprise software, Linux distributions, and open-source libraries, including zero-days and rapid weaponization.
Drone and counter-drone operations in ongoing geopolitical conflicts
Oct 2, 2026Reports cover drone attacks on critical infrastructure, military drone deployments, counter-drone technologies, and related investments amid ongoing regional and maritime conflicts.
AI autonomous agents driving breaches and governance challenges
Oct 2, 2026Clusters describe AI-powered autonomous agents breaching government and healthcare systems, AI-driven cyberattacks, AI-enhanced phishing and scams, and the resulting regulatory and governance challenges.
State-linked espionage and cyber operations targeting governments and critical infrastructure
Oct 2, 2026Multiple clusters highlight espionage campaigns, state-sponsored cyberattacks, surveillance activities, arrests, and law enforcement responses targeting governments, academia, critical infrastructure, and journalists.
Critical zero-day exploits in enterprise network and security products
Oct 2, 2026Multiple clusters report zero-day and critical vulnerabilities in enterprise network devices, security products, and virtualization software being actively exploited to gain unauthorized access and disrupt defenses.
Geopolitical tensions fueling cyber, kinetic, and hybrid warfare including disinformation
Oct 2, 2026Clusters reveal cyberattacks, drone strikes, disinformation campaigns, sanctions, and military escalations linked to conflicts involving Russia, Ukraine, Iran, China, and other actors.
Ransomware and malware campaigns disrupting critical infrastructure and healthcare
Oct 2, 2026Ongoing ransomware and malware campaigns target critical infrastructure, healthcare, government, legal, transportation, and other sectors, often combining extortion, data leaks, and destructive tactics.
AI-enhanced phishing, social engineering, and BEC campaigns
Oct 2, 2026Multiple clusters describe phishing and social engineering attacks targeting healthcare, education, military, and AI sectors using AI-driven deepfakes, QR codes, OAuth flows, and impersonation scams.
Cryptocurrency theft and laundering exploiting privacy protocols and smart contracts
Oct 2, 2026Clusters report large-scale cryptocurrency thefts, laundering through privacy-enhanced protocols, smart contract exploits, and related social engineering scams targeting crypto platforms and wallets.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
629 topicsNo longer detected as trending. Sorted newest archived first.
Nation-State Spyware Targeting Journalists, Activists, and Telecom Infrastructure
Sep 9, 2026Mercenary spyware campaigns and nation-state actors employ zero-click exploits, insider recruitment, covert communications, and telecom supply chain compromises to surveil political figures, activists, and support intelligence operations.
Active exploitation of critical vulnerabilities in network and security appliances
Sep 16, 2026Multiple clusters report critical remote code execution, privilege escalation, and zero-day vulnerabilities actively exploited in network and security appliances including SonicWall, Cisco, and others.
Advanced spyware campaigns targeting activists and journalists
Sep 7, 2026Sophisticated spyware operations employing zero-click exploits and direct user notifications continue to target activists, opposition figures, journalists, and vulnerable device users for surveillance and political control.
Targeted malware and fraud campaigns against regional and sector-specific communities this week
Sep 4, 2026Focused campaigns target Brazilian users, Southeast Asia, journalists, activists, and political groups with spyware, malware, and social engineering tailored to local contexts.
Surge in Autonomous AI-Powered Cyberattacks and Ransomware
Sep 3, 2026Emerging AI-powered cyberattacks include autonomous AI agents conducting intrusions, AI-enhanced ransomware campaigns, AI-enabled malware evasion, and AI-driven offensive operations accelerating attack sophistication across sectors.
Active Exploitation of Critical Linux and Open-Source Vulnerabilities
Sep 3, 2026Multiple critical vulnerabilities affecting Linux distributions such as Ubuntu, Fedora, SUSE, and related open-source libraries and packages have been discovered, patched, and actively exploited, impacting core system components and utilities.
Surveillance spyware and mercenary spyware targeting journalists, activists, and high-value mobile users
Sep 8, 2026Advanced spyware campaigns employ zero-click exploits and mercenary tools to surveil journalists, activists, immigration groups, and mobile device users, raising significant privacy and security concerns.
Ransomware Targeting Backups and Government with Novel Evasion Tactics
Sep 3, 2026Ransomware groups increasingly focus on disabling backup and recovery systems, targeting municipal, government, healthcare, and SMB sectors while employing new command-and-control frameworks and evasion techniques to hinder detection and restoration.
Zero-click spyware campaigns targeting journalists and activists
Sep 10, 2026Advanced spyware employing zero-click exploits and sophisticated surveillance techniques target journalists, activists, and mobile device users, prompting vendor alerts and security advisories.
State-Linked Spyware Campaigns Targeting Journalists and Activists
Sep 3, 2026State-affiliated actors and intelligence agencies deploy sophisticated malware frameworks, zero-click spyware, and covert communication methods to conduct espionage against journalists, activists, governments, and intelligence operations.
Zero-click spyware targeting journalists and activists
Sep 13, 2026Advanced spyware campaigns using zero-click vulnerabilities have targeted journalists and activists across multiple platforms and regions for covert surveillance.
Advanced Phishing and Social Engineering with Polymorphic and OAuth Evasion
Sep 3, 2026Sophisticated phishing and social engineering attacks use polymorphic pages, session hijacking, OAuth consent phishing, impersonation of trusted entities, and AI techniques to steal credentials and enable persistent unauthorized access across multiple sectors.
Active exploitation of network and enterprise device zero-days and backdoors
Sep 4, 2026Critical zero-day flaws, backdoors, and authentication bypass vulnerabilities in network devices, VPN appliances, and enterprise software are actively exploited by threat actors.
Ransomware campaigns targeting backups and leveraging social engineering this week
Sep 6, 2026Ransomware groups focus on disrupting backup and recovery systems while using social engineering and phishing to gain initial access, impacting healthcare, small organizations, and public sectors.
Malware Campaigns Exploiting Trojanized Installers and AI Brand Impersonation
Sep 3, 2026Malware distribution increasingly exploits tampered installers, fake game clients, developer and AI tools, and impersonation of popular AI brands to infect users and steal credentials.
Cryptocurrency Malware Campaigns and Law Enforcement Seizures
Sep 9, 2026Malware campaigns targeting cryptocurrency wallets, smart contracts, and financial ecosystems are accompanied by law enforcement seizures of illicit crypto assets linked to darknet markets.
AI-enhanced phishing and social engineering surge
Sep 2, 2026Recent phishing and social engineering attacks increasingly use voice phishing, impersonation of trusted entities, AI-driven automation, multi-stage malware, and targeted campaigns to steal credentials and deliver ransomware or infostealers.
AI-driven malware targeting cryptocurrency and finance
Sep 2, 2026Sophisticated malware and fraud campaigns employ geofencing, compiled bytecode, AI-driven automation, and evasion methods to steal cryptocurrency, target financial institutions, and exploit blockchain platforms.
Major cryptocurrency and blockchain protocol exploits causing financial losses this week
Sep 6, 2026DeFi and blockchain platforms suffer multi-million dollar thefts and network disruptions due to smart contract flaws and protocol vulnerabilities.
Critical RCE vulnerabilities actively exploited in major software platforms this week
Sep 1, 2026Multiple clusters report critical remote code execution (RCE) vulnerabilities in widely used enterprise, open-source, and infrastructure software actively exploited by attackers to gain unauthorized control.
Ransomware and supply chain attacks disrupt healthcare and government
Sep 2, 2026Ransomware campaigns and supply chain compromises continue to disrupt healthcare, education, government, and enterprise organizations, often leveraging identity theft and software supply chain vulnerabilities.
Phishing and social engineering campaigns using advanced evasion and AI techniques this week
Sep 1, 2026Recent phishing operations employ polymorphic and localized lures, voice phishing via collaboration platforms, AI-enabled fraud, and impersonation of officials or trusted brands to steal credentials, enable persistent access, and cause financial losses.
Cryptocurrency and blockchain platform exploits causing financial losses this week
Sep 1, 2026Exploits targeting cryptocurrency exchanges, DeFi protocols, and blockchain infrastructure involve price manipulation, smart contract flaws, malware, and token theft leading to significant financial damage.
AI-enhanced cyber threats leveraging automation, deepfakes, and prompt injection this week
Sep 1, 2026Clusters cover AI-driven phishing, autonomous attacks, deepfake misinformation and extortion, AI-enabled social engineering and impersonation scams, and prompt injection vulnerabilities exploited for unauthorized access and fraud.