◦ PUBLISHED SNAPSHOT

MENA Monthly Report — September 2026

Published snapshot · generated Sep 30, 2026 · 23:59 UTC · completed month

Point-in-time record of the MENA Monthly Report for 2026-09; later intelligence is not reflected — see the live monthly report.
Download Markdown
TLP:CLEARRAQIB-MENA-M-2026-09Disclosure is not limited. Corpus-wide, no tenant data.
34
Ransomware claims
▼4 vs last mo (38)
2
MENA-relevant KEV CVEs
tally · no delta
2
New MENA-relevant KEV
▲ new vs last mo
2
New activity groups
▲ new vs last mo
198
Newly observed
▲139 vs last mo (59)
11
Technique spikes
12-wk momentum · no delta

A deterministic, month-anchored executive digest of the MENA corpus — month totals with a same-span-vs-last-month delta, then a curated top-N by each surface’s own fixed rank. No item is a model-chosen "top threat." First-seen ≠ globally new; claims ≠ breaches; KEV/OSINT ≠ confirmed in-region exploitation; correlation ≠ attribution.

What mattered5

A curated top-6 by each surface’s own deterministic rank — not exhaustive. Every line links to the surface that owns the record. Each finding carries a rule-derived confidence (see legend).

Standing lenses

Longer-window context (90-day over-indexing, 12-week technique momentum) — not September events.

Technique momentum

Top ATT&CK techniques by 12-week reporting momentum (recent 4-week half vs prior 4 weeks) — a shift in reporting volume, not a month-over-month change and not confirmed in-region targeting.

TechniqueRecentPriorΔ 12-wkz
T1190.001 ↗20▲23.16
T1133 ↗20▲21.63
T1048 ↗20▲2-0.47
T1021.006 ↗20▲2-0.61
T1567.002 ↗20▲2-0.61

Intelligence gaps

What this report could not observe. Stating collection and method limits is part of the analysis — an absence here is a gap in visibility, not evidence of safety.

  • Exploited CVEs are reported as a month tally, not a month-over-month delta — last-mention semantics would overstate movement.
  • Technique signals are a 12-week reporting-momentum lens, not a month-over-month change and not confirmed in-region targeting.

Confidence

  • HIGH≥2 independent sources, or KEV-listed with an independent MENA in-region mention — corroborated by more than one report, not a bare claim.
  • MODA single reliable source, or corroborated but claim-based (e.g. multiple leak-site posts with no technical confirmation).
  • LOWA single uncorroborated source, a first-appearance-only observation, or an isolated claim.

Confidence rates the strength of the evidence observed, not the likelihood of a future event — this is a deterministic digest, not a forecast.

Data sources

  • Emerging feed — first-seen actors, malware families, C2 endpoints, brand lookalikes
  • Exploited-in-MENA board — CISA KEV cross-referenced to MENA OSINT mentions
  • Ransomware leak-site claims — MENA-filtered
  • Activity-group clustering — correlated OSINT campaigns
  • CISA KEV — MENA-relevant additions
  • Technique signals — 12-week ATT&CK reporting momentum

Have an intelligence requirement this digest should answer? Track a requirement in your workspace →

Aggregates the Emerging, Exploited-in-MENA, Ransomware, Campaigns, KEV and Signals surfaces over the UTC calendar month (first_seen / last_mentioned / claimed_at / date_added / to_at). Deterministic spine: every count, delta and ranked item is a fixed function of the corpus — no model in the data path. A month-to-date read compares the same elapsed span of the prior month (an apples-to-apples pace comparison); a completed month compares the full prior month.