A computed executive digest, not an editorial pick — deterministic month totals with a same-span-vs-last-month delta over the MENA corpus, refreshed each ETL run. Nothing here is a new finding: every stat and line links to the surface that owns the underlying record so you can verify it in place.
September 2026 is month-to-date — deltas compare the same elapsed span of last month, not its full total. A deterministic, month-anchored executive digest of the MENA corpus — month totals with a same-span-vs-last-month delta, then a curated top-N by each surface’s own fixed rank. No item is a model-chosen "top threat." First-seen ≠ globally new; claims ≠ breaches; KEV/OSINT ≠ confirmed in-region exploitation; correlation ≠ attribution.
A curated top-5 by each surface’s own deterministic rank — not exhaustive. Every line links to the surface that owns the record. Each finding carries a rule-derived confidence (see legend).
Longer-window context (90-day over-indexing, 12-week technique momentum) — not September events.
Top ATT&CK techniques by 12-week reporting momentum (recent 4-week half vs prior 4 weeks) — a shift in reporting volume, not a month-over-month change and not confirmed in-region targeting.
| Technique | Recent | Prior | Δ 12-wk | z |
|---|---|---|---|---|
| T1566 ↗ | 25 | 19 | ▲6 | -0.34 |
| T1059.001 ↗ | 8 | 3 | ▲5 | 0.00 |
| T1059.007 ↗ | 7 | 2 | ▲5 | -0.89 |
| T1105 ↗ | 11 | 8 | ▲3 | -0.52 |
| T1547.001 ↗ | 5 | 2 | ▲3 | 0.51 |
What this report could not observe. Stating collection and method limits is part of the analysis — an absence here is a gap in visibility, not evidence of safety.
Confidence rates the strength of the evidence observed, not the likelihood of a future event — this is a deterministic digest, not a forecast.
Have an intelligence requirement this digest should answer? Track a requirement in your workspace →
Aggregates the Emerging, Exploited-in-MENA, Ransomware, Campaigns, KEV and Signals surfaces over the UTC calendar month (first_seen / last_mentioned / claimed_at / date_added / to_at). Deterministic spine: every count, delta and ranked item is a fixed function of the corpus — no model in the data path. A month-to-date read compares the same elapsed span of the prior month (an apples-to-apples pace comparison); a completed month compares the full prior month.