Week 38 of 2026

The Watchtower from 14 Sep to 20 Sep 2026, in numbers: what our sensors recorded, where it came from and what changed on the block list. How the board works

· All weeks · · Atom feed

Attack-shaped requests
9,386+4,219 (+82%) on the week before
Addresses
602+240 (+66%) on the week before
Networks
61
Sites reached
36+1 (+3%) on the week before
Newly blocked
0same as the week before
Busiest hour (UTC)
802 requests

In short

In the week of 14 Sep to 20 Sep 2026 the sensors recorded 9,386 attack-shaped requests from 602 addresses on 61 networks.

They reached 36 sites.

The busiest day was Sunday 20 Sep with 3,539 requests; the quietest, Thursday 17 Sep, had 518.

The busiest single hour began at UTC: 802 requests.

By kind: hunting for secrets 47%, unclassified 46%, scanning 5%.

The single most common request shape, 4,194 times: an address made a request that matched no known pattern.

By sensor: edge 70%, web 30%.

The busiest network was AS396982 (Google LLC, cloud): 5,248 requests from 387 addresses, 36 of them blocked now.

No new address was blocked on our servers that week.

Against the week before: requests 5,167 to 9,386 (+82%), addresses 362 to 602 (+66%), new blocks unchanged at 0.

By day

Attack-shaped requests per day, 14 Sep to 20 Sep 2026 (UTC)
DayRequestsShare
Monday 1,073
Tuesday 1,219
Wednesday 586
Thursday 518
Friday 1,164
Saturday 1,287
Sunday 3,539

What they tried

By kind

Attack-shaped requests by attack type
Attack typeRequestsShare
hunting for secrets4,366
unclassified4,339
scanning474
injection173
fake crawlers27
scanning tools4
password spraying3

By sensor

Attack-shaped requests by sensor
SensorRequestsShare
edge6,589
web2,797

Most common request shapes

The ten most common request shapes
Kind of requestAttack typeRequestsShare
Made a request that matched no known patternunclassified4,194
Requested wp-config.php or a backup copy of it, hoping to read the database password in clear texthunting for secrets1,856
Requested a .env file, hoping to find API keys or database credentialshunting for secrets1,848
Probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilitiesscanning211
Requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroothunting for secrets202
Used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web rootinjection173
Was blocked at the edge without matching any specific attack signatureunclassified145
Enumerated WordPress REST API post IDs, a common precursor to username/content fingerprintingscanning126
Requested phpinfo.php, which dumps the full PHP configuration and environment if left in placehunting for secrets125
Fuzzed a short, random filename looking for a forgotten script that respondsscanning64

Busiest networks

The ten networks with the most attack-shaped requests
NetworkOrganisationTypeAddressesBlocked nowRequestsShare
AS396982Google LLCcloud387365,248
AS48090Techoff Srv Limitedhosting31282,458
AS218785Tc Datacenter Limitedhosting1513694
AS14956RouterHosting LLChosting63270
AS8075Microsoft Corporationcloud110121
AS14061DigitalOcean, LLChosting38297
AS14618Amazon.com, Inc.cloud5181
AS142430DIGI VPShosting1138
AS203861Miteflux Technologies Ltdhome broadband1037
AS211590Bucklog SARLhosting2232

Blocked now: of the addresses seen that week on the network, how many are blocked on our servers today.

Against the week before

This week against Week 37 of 2026
MeasureWeek 37 of 2026Week 38 of 2026Change
Attack-shaped requests5,1679,386+4,219 (+82%)
Addresses362602+240 (+66%)
Sites reached3536+1 (+3%)
Newly blocked00none

Week 37 of 2026 in full