Week 40 of 2026
The Watchtower from 28 Sep to 4 Oct 2026, in numbers: what our sensors recorded, where it came from and what changed on the block list. How the board works
- Attack-shaped requests
- 153,654+146,022 (+1,913%) on the week before
- Addresses
- 2,212+1,663 (+303%) on the week before
- Networks
- 534
- Sites reached
- 40+4 (+11%) on the week before
- Newly blocked
- 309+309 on the week before
- Busiest hour (UTC)
- 4,244 requests
In short
In the week of 28 Sep to 4 Oct 2026 the sensors recorded 153,654 attack-shaped requests from 2,212 addresses on 534 networks.
They reached 40 sites.
The busiest day was Tuesday 29 Sep with 32,768 requests; the quietest, Monday 28 Sep, had 3,330.
The busiest single hour began at UTC: 4,244 requests.
By kind: scanning 49%, hunting for secrets 37%, password spraying 4%.
The single most common request shape, 58,136 times: an address fuzzed a short, random filename looking for a forgotten script that responds.
By sensor: web 93%, edge 7%, the rest under 1%.
The busiest network was AS8075 (Microsoft Corporation, cloud): 61,200 requests from 116 addresses, 44 of them blocked now.
309 addresses were newly blocked on our servers: 156 on cloud networks, 112 on hosting networks, 41 on home broadband networks. 112 of them stay on the list with no end date.
Against the week before: requests 7,632 to 153,654 (+1,913%), addresses 549 to 2,212 (+303%), new blocks 0 to 309.
Commentary
Against the week before, requests rose from 7,632 to 153,654, a change of +1,913%, and addresses rose from 549 to 2,212, a change of +303%. New blocks rose from 0 to 309. Of those 309 new blocks, 156 sit on cloud networks, 112 on hosting networks and 41 on home broadband networks. 112 of them stay on the list with no end date.
By day
| Day | Requests | Share |
|---|---|---|
| Monday | 3,330 | |
| Tuesday | 32,768 | |
| Wednesday | 29,199 | |
| Thursday | 16,860 | |
| Friday | 23,946 | |
| Saturday | 20,854 | |
| Sunday | 26,697 |
What they tried
By kind
| Attack type | Requests | Share |
|---|---|---|
| scanning | 75,535 | |
| hunting for secrets | 56,913 | |
| password spraying | 6,589 | |
| scanning tools | 5,961 | |
| injection | 4,759 | |
| unclassified | 2,543 | |
| known exploits | 905 | |
| password guessing | 246 | |
| mail relay probing | 126 | |
| fake crawlers | 67 | |
| open proxy probing | 8 | |
| flooding | 2 |
By sensor
| Sensor | Requests | Share |
|---|---|---|
| web | 142,306 | |
| edge | 10,543 | |
| panel | 424 | |
| 341 | ||
| ssh | 23 | |
| ftp | 17 |
Most common request shapes
| Kind of request | Attack type | Requests | Share |
|---|---|---|---|
| Fuzzed a short, random filename looking for a forgotten script that responds | scanning | 58,136 | |
| Requested a .env file, hoping to find API keys or database credentials | hunting for secrets | 33,503 | |
| Requested xmlrpc.php, which exposes a multicall method commonly abused to spray WordPress credentials and relay pingback floods | password spraying | 6,589 | |
| Requested a common cloud/app secrets or credentials filename (AWS, GCP, Firebase, Kubernetes service-account token, SSH, master key) from a wordlist, hoping one was left in the webroot | hunting for secrets | 6,130 | |
| Used a scripting or HTTP client library to probe a sensitive path directly, consistent with automated scanning rather than a browser visit | scanning tools | 5,281 | |
| Used a directory-traversal segment (literal or percent-encoded ../) in the request path to try to escape the web root | injection | 4,321 | |
| Requested a WordPress core file used to fingerprint the installed version and active plugins | scanning | 4,001 | |
| Probed a WordPress admin/content path used to fingerprint the installation or hunt for an exposed upload/plugin surface | scanning | 3,655 | |
| Probed the WordPress REST API batch endpoint, often used to fingerprint or chain other WordPress vulnerabilities | scanning | 2,802 | |
| Requested a database dump or site archive by its common backup filename | hunting for secrets | 2,226 |
Busiest networks
| Network | Organisation | Type | Addresses | Blocked now | Requests | Share |
|---|---|---|---|---|---|---|
| AS8075 | Microsoft Corporation | cloud | 116 | 44 | 61,200 | |
| AS396982 | Google LLC | cloud | 334 | 80 | 49,225 | |
| AS48090 | Techoff Srv Limited | hosting | 52 | 47 | 9,662 | |
| AS211590 | Bucklog SARL | hosting | 10 | 8 | 6,979 | |
| AS218785 | Tc Datacenter Limited | hosting | 34 | 21 | 4,913 | |
| AS208137 | Feo Prest SRL | hosting | 3 | 3 | 1,778 | |
| AS14061 | DigitalOcean, LLC | hosting | 253 | 14 | 1,763 | |
| AS202412 | Omegatech LTD | hosting | 11 | 4 | 1,630 | |
| AS197170 | TechTies Inc. | hosting | 26 | 15 | 1,496 | |
| AS213790 | Limited Network LTD | home broadband | 1 | 1 | 953 |
Blocked now: of the addresses seen that week on the network, how many are blocked on our servers today.
Block list
New blocks by network type
| Network type | Addresses | Share |
|---|---|---|
| cloud | 156 | |
| hosting | 112 | |
| home broadband | 41 |
How they got there
- By score
- 309
- Fast-track rule
- 0
- No end date
- 112hosting networks
- On the public list
- 298of the newly blocked
Against the week before
| Measure | Week 39 of 2026 | Week 40 of 2026 | Change |
|---|---|---|---|
| Attack-shaped requests | 7,632 | 153,654 | +146,022 (+1,913%) |
| Addresses | 549 | 2,212 | +1,663 (+303%) |
| Sites reached | 36 | 40 | +4 (+11%) |
| Newly blocked | 0 | 309 | +309 |