Week 37 of 2026

The Watchtower from 7 Sep to 13 Sep 2026, in numbers: what our sensors recorded, where it came from and what changed on the block list. How the board works

All weeks · · Atom feed

Attack-shaped requests
5,167
Addresses
362
Networks
44
Sites reached
35
Newly blocked
0
Busiest hour (UTC)
556 requests

In short

In the week of 7 Sep to 13 Sep 2026 the sensors recorded 5,167 attack-shaped requests from 362 addresses on 44 networks.

They reached 35 sites.

The busiest day was Saturday 12 Sep with 1,785 requests; the quietest, Thursday 10 Sep, had 297.

The busiest single hour began at UTC: 556 requests.

By kind: unclassified 64%, hunting for secrets 31%, scanning 4%.

The single most common request shape, 3,194 times: an address made a request that matched no known pattern.

By sensor: edge 100%.

The busiest network was AS396982 (Google LLC, cloud): 2,518 requests from 227 addresses, 8 of them blocked now.

No new address was blocked on our servers that week.

By day

Attack-shaped requests per day, 7 Sep to 13 Sep 2026 (UTC)
DayRequestsShare
Monday 0
Tuesday 0
Wednesday 458
Thursday 297
Friday 1,380
Saturday 1,785
Sunday 1,247

What they tried

By kind

Attack-shaped requests by attack type
Attack typeRequestsShare
unclassified3,313
hunting for secrets1,618
scanning186
fake crawlers28
injection11
scanning tools10
known exploits1

By sensor

Attack-shaped requests by sensor
SensorRequestsShare
edge5,167

Most common request shapes

The ten most common request shapes
Kind of requestAttack typeRequestsShare
Made a request that matched no known patternunclassified3,194
Requested wp-config.php or a backup copy of it, hoping to read the database password in clear texthunting for secrets1,488
Probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilitiesscanning136
Was blocked at the edge without matching any specific attack signatureunclassified119
Requested a .env file, hoping to find API keys or database credentialshunting for secrets53
Enumerated WordPress REST API post IDs, a common precursor to username/content fingerprintingscanning45
Claimed to be Googlebot while POSTing, something the real crawler never doesfake crawlers28
Used Vite dev server's @fs/ path to try to read arbitrary files outside the project roothunting for secrets27
Probed for an exposed .git directory to download the site's source history and confighunting for secrets17
Requested an AWS credentials file left in a web-accessible path by mistakehunting for secrets12

Busiest networks

The ten networks with the most attack-shaped requests
NetworkOrganisationTypeAddressesBlocked nowRequestsShare
AS396982Google LLCcloud22782,518
AS48090Techoff Srv Limitedhosting28232,016
AS142430DIGI VPShosting11119
AS215930Cipher Operations Doo Beograd - Novi Beogradhome broadband5263
AS14956RouterHosting LLChosting3262
AS63949Akamai Connected Cloudhosting11050
AS14061DigitalOcean, LLChosting12542
AS14618Amazon.com, Inc.cloud3042
AS208137Feo Prest SRLhosting1130
AS218785Tc Datacenter Limitedhosting5221

Blocked now: of the addresses seen that week on the network, how many are blocked on our servers today.