Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
27 topics
Active exploitation of critical RCE and privilege escalation zero-days in enterprise and open-source software
Oct 2, 2026Multiple clusters report urgent and active exploitation of critical remote code execution and privilege escalation vulnerabilities across widely used enterprise software, Linux distributions, and open-source libraries, including zero-days and rapid weaponization.
Drone and counter-drone operations in ongoing geopolitical conflicts
Oct 2, 2026Reports cover drone attacks on critical infrastructure, military drone deployments, counter-drone technologies, and related investments amid ongoing regional and maritime conflicts.
AI autonomous agents driving breaches and governance challenges
Oct 2, 2026Clusters describe AI-powered autonomous agents breaching government and healthcare systems, AI-driven cyberattacks, AI-enhanced phishing and scams, and the resulting regulatory and governance challenges.
State-linked espionage and cyber operations targeting governments and critical infrastructure
Oct 2, 2026Multiple clusters highlight espionage campaigns, state-sponsored cyberattacks, surveillance activities, arrests, and law enforcement responses targeting governments, academia, critical infrastructure, and journalists.
Critical zero-day exploits in enterprise network and security products
Oct 2, 2026Multiple clusters report zero-day and critical vulnerabilities in enterprise network devices, security products, and virtualization software being actively exploited to gain unauthorized access and disrupt defenses.
Geopolitical tensions fueling cyber, kinetic, and hybrid warfare including disinformation
Oct 2, 2026Clusters reveal cyberattacks, drone strikes, disinformation campaigns, sanctions, and military escalations linked to conflicts involving Russia, Ukraine, Iran, China, and other actors.
Ransomware and malware campaigns disrupting critical infrastructure and healthcare
Oct 2, 2026Ongoing ransomware and malware campaigns target critical infrastructure, healthcare, government, legal, transportation, and other sectors, often combining extortion, data leaks, and destructive tactics.
AI-enhanced phishing, social engineering, and BEC campaigns
Oct 2, 2026Multiple clusters describe phishing and social engineering attacks targeting healthcare, education, military, and AI sectors using AI-driven deepfakes, QR codes, OAuth flows, and impersonation scams.
Cryptocurrency theft and laundering exploiting privacy protocols and smart contracts
Oct 2, 2026Clusters report large-scale cryptocurrency thefts, laundering through privacy-enhanced protocols, smart contract exploits, and related social engineering scams targeting crypto platforms and wallets.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
629 topicsNo longer detected as trending. Sorted newest archived first.
State-sponsored spear-phishing and insider espionage campaigns this week
Sep 4, 2026State-linked actors conduct espionage against government, defense, and critical sectors using spear-phishing, fake personas, and insider infiltration to steal sensitive data.
State-sponsored espionage using novel malware and identity fraud this week
Sep 7, 2026Nation-state actors conduct espionage campaigns using advanced malware, backdoors, SIM card trafficking, and fraudulent remote employment schemes to infiltrate government, defense, and critical infrastructure sectors.
Deepfake scams prompt new legal and regulatory actions this week
Sep 6, 2026AI-generated deepfakes are exploited in financial fraud, identity scams, and extortion campaigns, triggering legal actions and increased focus on detection and regulation.
Major DeFi and crypto platform exploits and phishing causing multi-million dollar losses
Sep 4, 2026Multiple blockchain and DeFi platforms have suffered large-scale exploits, governance attacks, and phishing scams resulting in halted operations and significant token theft.
Major DeFi Platform Exploits and Financial Losses
Sep 3, 2026Multiple blockchain and DeFi platforms have suffered major exploits and governance attacks resulting in multi-million dollar token thefts, protocol shutdowns, and large-scale financial losses.
DeFi and cryptocurrency platform exploits and phishing campaigns this week
Sep 5, 2026Several blockchain and DeFi platforms suffered large-scale exploits, token thefts, and phishing scams targeting wallet users and crypto governance mechanisms.
DeFi protocol exploits and cryptocurrency theft via smart contract flaws and phishing
Sep 8, 2026Decentralized finance platforms suffer multi-million-dollar losses due to price oracle and contract flaws, while phishing campaigns target blockchain users and exchanges for token theft.
Exploitation of Cloud and Enterprise Platform Vulnerabilities for Unauthorized Access and Persistence
Aug 31, 2026Attackers leverage vulnerabilities, leaked credentials, and malware abusing cloud services and developer platforms to gain unauthorized access, maintain persistence, and conduct stealthy command-and-control operations.
DeFi and Blockchain Protocol Exploits Causing Major Financial Losses and Governance Manipulation
Aug 31, 2026Large-scale exploits targeting DeFi platforms and blockchain protocols exploit smart contract flaws and governance vulnerabilities, resulting in token theft, unauthorized minting, and transaction fraud.
This Week’s AI-Enabled Cyber Attacks and Defenses
Aug 30, 2026Clusters describe AI-powered malware, autonomous AI agents conducting malicious activities, AI-driven social engineering and phishing campaigns, AI-related vulnerabilities in software and hardware, and AI tools used both offensively and defensively in cyber operations.
Advanced Phishing and Social Engineering Campaigns Targeting Credentials Across Sectors
Aug 31, 2026Sophisticated phishing operations employ impersonation, polymorphic pages, localization, voice cloning, and targeting of government, corporate, cryptocurrency users, and public officials to steal credentials and maintain persistent access.
Active Exploitation of Critical RCE Vulnerabilities in Enterprise and Open-Source Software
Aug 31, 2026Multiple critical remote code execution (RCE) vulnerabilities across enterprise platforms, open-source libraries, plugins, and embedded devices are being actively exploited, enabling attackers to execute arbitrary code and escalate privileges remotely.
AI-Driven Cyberattacks: Prompt Injection, Autonomous Agents, and Deepfake Social Engineering
Aug 31, 2026Emerging AI-powered threats encompass prompt injection attacks on language models, autonomous AI agents conducting unauthorized actions, and AI-enhanced social engineering such as deepfake-enabled scams and impersonation.
Surge in AI-enhanced social engineering, phishing, and deepfake attacks
Aug 29, 2026Threat actors increasingly leverage AI-driven techniques including deepfakes, AI-enabled phishing, prompt injection, and impersonation scams to conduct sophisticated social engineering and fraud campaigns across sectors.
Ransomware and Malware Exploiting Critical Vulnerabilities in Government and Cloud
Aug 30, 2026Ransomware and malware groups increasingly exploit critical software flaws to compromise government agencies, SMBs, industrial infrastructure, cloud platforms, and financial sectors, employing evolving tactics including RaaS and extortion.
Supply chain attacks targeting software development and open-source ecosystems
Aug 29, 2026Attackers exploit vulnerabilities in version control systems, open-source package ecosystems, and procurement processes to compromise software supply chains and development infrastructure.
Supply Chain Attacks Targeting Developer Tools and Software Ecosystems
Aug 30, 2026Attackers target software supply chains through vulnerabilities in version control systems, developer platforms, and open-source infrastructure to inject malicious code and compromise downstream users.
Malicious Browser Extensions and Malware Targeting Crypto Wallets and Vehicle IoT
Aug 30, 2026Coordinated campaigns compromise browser extensions to steal crypto wallet credentials and deploy Android malware targeting vehicle firmware for ad fraud, botnets, and data theft.
Cybercrime Migration to Encrypted Messaging Platforms and Infiltration via Fake Personas
Aug 31, 2026Cybercriminal groups increasingly shift operations from traditional dark web forums to encrypted apps like Telegram and use fabricated identities to infiltrate organizations and conduct fraud.
Cybercrime migration to Telegram communication platform
Sep 7, 2026Cybercriminal groups increasingly shift coordination and communication from traditional dark web forums to platforms like Telegram, reflecting evolving operational tactics and community dynamics.
Emerging cyber attacks on space, satellite, and AI infrastructure
Sep 4, 2026Emerging threats exploit vulnerabilities in space and satellite systems as well as AI hardware and software, including GPU attacks and AI platform credential theft.
Critical RCE and command injection vulnerabilities actively exploited this week
Aug 29, 2026Multiple clusters report critical remote code execution (RCE) and command injection vulnerabilities in widely used software, enterprise platforms, and infrastructure being actively exploited or urgently patched.
Advanced Phishing and Social Engineering Targeting Credentials and Crypto
Aug 30, 2026Multiple campaigns leverage sophisticated evasion techniques, AI automation, deepfakes, and localized targeting to steal corporate, consumer, and cryptocurrency credentials, enabling persistent access and financial fraud.
State-sponsored cyber espionage using advanced malware and OAuth exploitation
Aug 29, 2026Clusters describe state-linked espionage campaigns deploying sophisticated malware, evasion tactics, OAuth exploitation, and phishing to target governments, academia, and diplomatic entities.