Fenestra TI's Threat Landscape for September 2026 is now available. Each edition draws on Fenestra's own collection and analysis to give security, risk and intelligence teams a grounded read on the month.
September's common thread: across the geospatial, aviation, maritime and cyber domains, the most significant attacks and near-misses landed on privately owned infrastructure, and the owners were often the first to act.
Key Findings
- Terrorism and conflict gained ground. Terrorism rose from 8.5% to 11.7% of geolocated security events, and armed conflict from 19.9% to 22.4%, driven by the Houthi campaign against Saudi Arabia and Israeli strikes in Lebanon. Protest fell back after a heavy August.
- The Red Sea front moved ashore. The Houthis seized Mocha and islands controlling the Bab el-Mandeb, and struck Saudi refining, pipeline and airport targets, while tanker attacks around Hormuz continued all month.
- Russian sabotage in Europe is now openly attributed. Germany and Estonia formally blamed Russia for attacks on European soil. Counting each development once, we recorded 39 in September against 15 in August; the rise came from attributions, arrests and charges, while the number of new incidents barely changed.
- Ransomware became less concentrated, but not less dangerous. The top three groups' share of victims fell from about a third to just under a quarter, and network-edge vulnerabilities remained the clearest way in.
- AI access is now an underground commodity. AI-related content roughly doubled its share of underground forum discussion, and stolen AI and cloud API keys were openly advertised for sale.
- Exposed industrial systems are found in days. Our industrial-control decoy was probed by more than 150 distinct addresses in its first week; the most probed protocol is used in electricity-grid control.
Inside the Report
- Geospatial & Physical Security — month-on-month shares of terrorism, conflict, violence, crime and activism, and the countries driving the change.
- Maritime & Aviation — Hormuz, the Houthi advance on the Bab el-Mandeb, the return of Somali piracy, the Black Sea and Mediterranean, and cyber attacks on ship systems.
- Ransomware — the leaderboard, sectors and countries, and the vulnerabilities exploited this month.
- Internet Signals — the first month of Fenestra's internet sensor network, and how stolen access moves through the underground.
- Cyber Underground — the trade in stolen AI keys, and how fast edge-device zero-days reach the forums.
- Spotlights — Russian hybrid sabotage in Europe, and ShinyHunters' escalation after a leader's arrest.
Download the full report (PDF)
Get in touch if you'd like to discuss how these trends apply to your organisation, its supply chains or its operating locations.
Information correct at time of writing (1 October 2026). Some situations described, including ongoing investigations, may have developed since.
