Week 40 of 2026

The Watchtower from 28 Sep to 4 Oct 2026, in numbers: what our sensors recorded, where it came from and what changed on the block list. How the board works

· All weeks · Atom feed

Attack-shaped requests
153,654+146,022 (+1,913%) on the week before
Addresses
2,212+1,663 (+303%) on the week before
Networks
534
Sites reached
40+4 (+11%) on the week before
Newly blocked
309+309 on the week before
Busiest hour (UTC)
4,244 requests

In short

In the week of 28 Sep to 4 Oct 2026 the sensors recorded 153,654 attack-shaped requests from 2,212 addresses on 534 networks.

They reached 40 sites.

The busiest day was Tuesday 29 Sep with 32,768 requests; the quietest, Monday 28 Sep, had 3,330.

The busiest single hour began at UTC: 4,244 requests.

By kind: scanning 49%, hunting for secrets 37%, password spraying 4%.

The single most common request shape, 58,136 times: an address fuzzed a short, random filename looking for a forgotten script that responds.

By sensor: web 93%, edge 7%, the rest under 1%.

The busiest network was AS8075 (Microsoft Corporation, cloud): 61,200 requests from 116 addresses, 44 of them blocked now.

309 addresses were newly blocked on our servers: 156 on cloud networks, 112 on hosting networks, 41 on home broadband networks. 112 of them stay on the list with no end date.

Against the week before: requests 7,632 to 153,654 (+1,913%), addresses 549 to 2,212 (+303%), new blocks 0 to 309.

Commentary

Over 28 Sep to 4 Oct 2026 our sensors logged 153,654 attack-shaped requests from 2,212 addresses spread across 534 networks, reaching 40 sites. Tuesday 29 Sep was the busiest day with 32,768 requests, while Monday 28 Sep was the quietest with 3,330. The busiest network was AS8075, Microsoft Corporation, cloud, with 61,200 requests from 116 addresses. Most traffic came through the web sensor, and most of it was scanning or hunting for secrets, with the single most common request shape a fuzzed short random filename, seen 58,136 times.

Against the week before, requests rose from 7,632 to 153,654, a change of +1,913%, and addresses rose from 549 to 2,212, a change of +303%. New blocks rose from 0 to 309. Of those 309 new blocks, 156 sit on cloud networks, 112 on hosting networks and 41 on home broadband networks. 112 of them stay on the list with no end date.

By day

Attack-shaped requests per day, 28 Sep to 4 Oct 2026 (UTC)
DayRequestsShare
Monday 3,330
Tuesday 32,768
Wednesday 29,199
Thursday 16,860
Friday 23,946
Saturday 20,854
Sunday 26,697

What they tried

By kind

Attack-shaped requests by attack type
Attack typeRequestsShare
scanning75,535
hunting for secrets56,913
password spraying6,589
scanning tools5,961
injection4,759
unclassified2,543
known exploits905
password guessing246
mail relay probing126
fake crawlers67
open proxy probing8
flooding2

By sensor

Attack-shaped requests by sensor
SensorRequestsShare
web142,306
edge10,543
panel424
mail341
ssh23
ftp17

Most common request shapes

The ten most common request shapes
Kind of requestAttack typeRequestsShare
Fuzzed a short, random filename looking for a forgotten script that respondsscanning58,136
Requested a .env file, hoping to find API keys or database credentialshunting for secrets33,503
Requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floodspassword spraying6,589
Requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroothunting for secrets6,130
Used a scripting or HTTP client library to probe a sensitive path directly, consistent with automated scanning rather than a browser visitscanning tools5,281
Used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web rootinjection4,321
Requested a WordPress core file used to fingerprint the installed version and active pluginsscanning4,001
Probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surfacescanning3,655
Probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilitiesscanning2,802
Requested a database dump or site archive by its common backup filenamehunting for secrets2,226

Busiest networks

The ten networks with the most attack-shaped requests
NetworkOrganisationTypeAddressesBlocked nowRequestsShare
AS8075Microsoft Corporationcloud1164461,200
AS396982Google LLCcloud3348049,225
AS48090Techoff Srv Limitedhosting52479,662
AS211590Bucklog SARLhosting1086,979
AS218785Tc Datacenter Limitedhosting34214,913
AS208137Feo Prest SRLhosting331,778
AS14061DigitalOcean, LLChosting253141,763
AS202412Omegatech LTDhosting1141,630
AS197170TechTies Inc.hosting26151,496
AS213790Limited Network LTDhome broadband11953

Blocked now: of the addresses seen that week on the network, how many are blocked on our servers today.

Block list

New blocks by network type

Addresses newly blocked that week, by network type
Network typeAddressesShare
cloud156
hosting112
home broadband41

How they got there

By score
309
Fast-track rule
0
No end date
112hosting networks
On the public list
298of the newly blocked

Against the week before

This week against Week 39 of 2026
MeasureWeek 39 of 2026Week 40 of 2026Change
Attack-shaped requests7,632153,654+146,022 (+1,913%)
Addresses5492,212+1,663 (+303%)
Sites reached3640+4 (+11%)
Newly blocked0309+309

Week 39 of 2026 in full