Smart Topics
Smart Topics group related clusters into the story arcs that actually matter this week, so instead of scrolling thirty headlines, you read one topic. ThreatCluster AI scans the feed, finds narratives that cut across actors and incidents, and curates them daily.
Live Smart Topics
27 topics
Active exploitation of critical RCE and privilege escalation zero-days in enterprise and open-source software
Oct 2, 2026Multiple clusters report urgent and active exploitation of critical remote code execution and privilege escalation vulnerabilities across widely used enterprise software, Linux distributions, and open-source libraries, including zero-days and rapid weaponization.
Drone and counter-drone operations in ongoing geopolitical conflicts
Oct 2, 2026Reports cover drone attacks on critical infrastructure, military drone deployments, counter-drone technologies, and related investments amid ongoing regional and maritime conflicts.
AI autonomous agents driving breaches and governance challenges
Oct 2, 2026Clusters describe AI-powered autonomous agents breaching government and healthcare systems, AI-driven cyberattacks, AI-enhanced phishing and scams, and the resulting regulatory and governance challenges.
State-linked espionage and cyber operations targeting governments and critical infrastructure
Oct 2, 2026Multiple clusters highlight espionage campaigns, state-sponsored cyberattacks, surveillance activities, arrests, and law enforcement responses targeting governments, academia, critical infrastructure, and journalists.
Critical zero-day exploits in enterprise network and security products
Oct 2, 2026Multiple clusters report zero-day and critical vulnerabilities in enterprise network devices, security products, and virtualization software being actively exploited to gain unauthorized access and disrupt defenses.
Geopolitical tensions fueling cyber, kinetic, and hybrid warfare including disinformation
Oct 2, 2026Clusters reveal cyberattacks, drone strikes, disinformation campaigns, sanctions, and military escalations linked to conflicts involving Russia, Ukraine, Iran, China, and other actors.
Ransomware and malware campaigns disrupting critical infrastructure and healthcare
Oct 2, 2026Ongoing ransomware and malware campaigns target critical infrastructure, healthcare, government, legal, transportation, and other sectors, often combining extortion, data leaks, and destructive tactics.
AI-enhanced phishing, social engineering, and BEC campaigns
Oct 2, 2026Multiple clusters describe phishing and social engineering attacks targeting healthcare, education, military, and AI sectors using AI-driven deepfakes, QR codes, OAuth flows, and impersonation scams.
Cryptocurrency theft and laundering exploiting privacy protocols and smart contracts
Oct 2, 2026Clusters report large-scale cryptocurrency thefts, laundering through privacy-enhanced protocols, smart contract exploits, and related social engineering scams targeting crypto platforms and wallets.
Russian energy sector targeting and threats
May 29, 2026Cyber activities and physical threats involving Russian actors targeting energy infrastructure and resources.
Russian government targeting government sectors
May 29, 2026Cyber activities by Russian state actors aimed at government entities across various regions and sectors.
Iranian DDoS activity targeting regional services
May 29, 2026This topic covers DDoS campaigns originating from Iran aimed at various sectors and infrastructure within the region.
German government targeting cyber threat actors
May 29, 2026Cybersecurity stories involving German government entities facing or responding to cyber threats and attacks.
Canadian energy sector targeted by cyber threats
May 29, 2026Cybersecurity stories involving Canadian energy companies and infrastructure, highlighting threat actors and their targeting activities.
Iranian actors targeting energy infrastructure
May 29, 2026Cyber threat activity involving Iranian entities targeting energy sector infrastructure and related systems.
Chinese government targeting international research institutions
May 29, 2026Cyber activities linked to Chinese government entities targeting global research projects and academic institutions.
Chinese financial sector targeting and defense activities
May 29, 2026Cyber threat activities involving Chinese financial institutions, including targeted attacks, partnerships, and regulatory responses.
North Korean Lazarus Group targeting cryptocurrency platforms
May 29, 2026Cyber threat activity involving North Korea's Lazarus Group focusing on cryptocurrency exchanges, wallets, and blockchain infrastructure.
Indian government targeting digital infrastructure
May 29, 2026Cyber threat activities by actors targeting India's government digital infrastructure and online services.
Chinese transportation sector cyber activities
May 29, 2026Monitoring cyber operations and vulnerabilities targeting China's transportation infrastructure and related entities.
Indian healthcare sector targeted by cyber threat actors
May 29, 2026Cybersecurity stories involving Indian healthcare organizations facing attacks, vulnerabilities, or malware campaigns.
Canadian financial sector targeted by cyber threats
May 29, 2026Cyber threat actors are actively targeting Canada's financial industry through various attack vectors, impacting institutions and infrastructure.
Russian DDoS activity targeting infrastructure
May 29, 2026Analysis of distributed denial-of-service campaigns originating from Russia aimed at various sectors and services.
Indian financial sector cybersecurity activity
May 29, 2026Monitoring cyber operations and threats targeting India's financial industry, including malware, hacking groups, and defense efforts.
German supply chain actors targeted by malicious packages
May 29, 2026Cyber threat activity involving German entities compromised through supply chain attacks on software and hardware components.
German financial sector targeted by cyber threat actors
May 29, 2026Cyber threat groups are actively targeting financial institutions in Germany through various attack methods and malware campaigns.
TeamPCP supply chain activity
May 29, 2026Analysis of supply chain attacks involving TeamPCP targeting software packages, cloud services, and development tools.
Archived Smart Topics
629 topicsNo longer detected as trending. Sorted newest archived first.
Active Exploitation of Critical RCE Vulnerabilities in Popular Software
Aug 30, 2026Multiple clusters report active exploitation of critical remote code execution (RCE) and command injection vulnerabilities across widely used open-source, enterprise, and Linux software platforms, including WordPress plugins and gaming software.
Active exploitation of critical RCE and privilege escalation vulnerabilities
Aug 28, 2026Multiple clusters report active exploitation of critical remote code execution, command injection, authentication bypass, and privilege escalation vulnerabilities in widely used software, platforms, and enterprise products, causing urgent security risks.
Ransomware and Supply Chain Attacks Impacting Healthcare, Government, Industrial, and Crypto Sectors
Aug 31, 2026Ransomware campaigns and supply chain compromises increasingly target healthcare, government agencies, SMBs, industrial environments, cloud platforms, and cryptocurrency ecosystems causing operational disruption and financial losses.
Supply chain attacks and ransomware impacting healthcare and software providers this week
Sep 1, 2026Ransomware and supply chain compromises affect healthcare, software, and large organizations through compromised service providers and software dependencies.
AI-driven offensive tools, prompt injection, and deepfake fraud
Aug 28, 2026Clusters highlight AI-assisted offensive and defensive cybersecurity tools, prompt injection and AI model vulnerabilities in developer platforms, AI-generated deepfakes used for misinformation and fraud, and AI-enhanced social engineering campaigns.
New hardware and protocol exploits enable privilege escalation
Sep 2, 2026New vulnerabilities at the hardware level, including GPUs, and web protocol exploits like HTTP request smuggling facilitate privilege escalation and large-scale account hijacking.
Ransomware and cybercrime disrupting critical infrastructure and financial sectors
Aug 29, 2026Ransomware gangs and cybercriminal groups are causing operational disruptions and financial impacts across government agencies, industrial firms, SMBs, and financial institutions using evolving tactics including RaaS and AI tools.
Spike in Deepfake and AI-Generated Content Threats in Fraud and Misinformation
Sep 3, 2026AI-generated deepfakes are increasingly used in political misinformation, financial fraud, and impersonation scams targeting high-profile individuals and sectors, while detection and regulatory efforts are being deployed to mitigate these risks.
AI-enabled deepfake and voice impersonation scams causing high-value fraud
Aug 27, 2026Clusters highlight the rise of AI-driven deepfake and voice impersonation scams used in social engineering to defraud individuals, investors, and organizations, alongside emerging detection and defense efforts.
Active exploitation of critical RCE and authentication bypass vulnerabilities
Aug 27, 2026Multiple clusters report active exploitation of critical remote code execution, authentication bypass, and privilege escalation vulnerabilities across widely used enterprise, open-source, and consumer software platforms.
Ransomware and financially motivated cybercrime disrupting government, industrial, and enterprise sectors
Aug 28, 2026Ransomware gangs and malware strains increasingly disrupt government agencies, SMBs, industrial organizations, cloud platforms, and financial institutions with impactful extortion and data theft campaigns.
Ransomware campaigns leveraging data theft and targeting government, SMB, healthcare, and industrial sectors
Aug 27, 2026Ransomware groups increasingly combine data theft extortion with attacks on government agencies, small and mid-sized businesses, healthcare, education, and industrial/cloud environments using evolving tactics.
Critical infrastructure and national security targeted by cyber and physical attacks
Aug 27, 2026Clusters highlight cyberattacks on critical infrastructure, national emergency responses, and drone strikes impacting logistics and power systems, prompting increased state security measures.
State-sponsored cyber espionage and operations targeting critical infrastructure and high-value individuals
Aug 28, 2026Clusters describe state actors conducting spear-phishing, advanced malware campaigns, OAuth exploitation, and cyber or physical attacks targeting critical infrastructure, government agencies, officials, and social platforms.
Active exploitation of critical RCE and privilege escalation vulnerabilities in popular software
Aug 26, 2026Multiple clusters report urgent active exploitation of critical remote code execution (RCE) and privilege escalation vulnerabilities across popular enterprise, cloud, open-source, and plugin software platforms, demanding immediate patching.
Advanced phishing and social engineering targeting high-value victims
Aug 26, 2026Sophisticated phishing and social engineering attacks employ evasion tactics, impersonation, session hijacking, and MFA bypass to target security teams, cryptocurrency users, journalists, activists, and financial institutions.
Phishing and social engineering campaigns targeting credentials and enabling account takeover
Aug 28, 2026Multiple campaigns use phishing, fake recruiters, SIM swapping, credential stuffing, and social engineering to steal credentials and enable persistent account access for corporate, consumer, high-profile, and crypto users.
Critical Linux and edge device vulnerabilities enabling remote compromise
Aug 26, 2026New critical flaws and botnets targeting Linux-based edge devices, distributions, and hardware/firmware components enable remote code execution and botnet recruitment.
Malware campaigns with novel evasion and niche platform targeting
Aug 29, 2026Recent malware campaigns employ innovative evasion methods such as emoji obfuscation and novel delivery vectors, targeting gaming communities, macOS users, automotive Android systems, and leveraging cloud/developer platforms for command and control.
Cryptocurrency ecosystem under attack: wallet exploits, governance manipulation, and phishing
Aug 26, 2026Clusters highlight exploits targeting crypto wallets, DeFi governance, blockchain protocols, phishing scams, token theft, and data breaches impacting cryptocurrency platforms and users.
Security incidents disrupting Cosmos EVM and blockchain protocols
Aug 26, 2026Clusters describe security incidents, exploits, and chain halts affecting Cosmos EVM modules and related blockchain tokens, disrupting decentralized finance operations.
Advanced Phishing and Social Engineering Campaigns Using Novel Evasion
Aug 25, 2026Emerging phishing and social engineering attacks use sophisticated evasion, impersonation, and novel vectors such as Browser-in-the-Browser, SEO poisoning, QR codes, and session-token theft to hijack accounts and defraud financial, crypto, and high-profile targets.
State-linked cyber operations targeting critical infrastructure and espionage
Aug 26, 2026Nation-state and mercenary actors conduct cyber and physical attacks on energy, industrial sites, communications infrastructure, and espionage campaigns leveraging OAuth, phishing, and device seizures.
Critical WordPress plugin vulnerabilities enabling unauthorized access and code execution this week
Sep 1, 2026Multiple critical vulnerabilities in WordPress plugins allow unauthorized access, remote code execution, and facilitate malware distribution through compromised sites.