Daniele Garofalo Monitoring

Daniele Garofalo Monitoring

The Operational Turn

What Changed in Global Security This Week? Weekly Threat Shift | Issue #16

Daniele Garofalo's avatar
Daniele Garofalo
Sep 02, 2026
∙ Paid

Executive Snapshot Issue #16

The reporting period of 26 August–1 September marked a significant transition from threat indicators to operational manifestation. Several dynamics monitored across previous issues moved closer to, or reached, the point of execution: jihadist mobilisation remained connected to both foreign training and domestic attack planning; adolescent extremist networks produced increasingly specific attack preparations; suspected Iranian-linked violence in the United Kingdom generated criminal convictions; and European defence and logistics infrastructure faced increasingly credible sabotage activity.

Germany’s attribution of the Leipzig/Halle incident to Russia indicates a significant escalation, but the likelihood of similar future attacks remains uncertain. Clarifying this can help security officials assess the immediate threat level and prioritise resources accordingly.

The same week, Polish prosecutors opened a terrorism and foreign-intelligence investigation after an explosive-incendiary device was allegedly used to set fire to facilities belonging to WB Electronics, a major Polish defence company producing unmanned systems used by Ukraine. Meanwhile, developments in Norway and Germany demonstrated that violent extremist mobilisation continues to evolve at the individual and small-network level.

The defining shift, therefore, is not simply an increase in incidents. Threats we observed in the preparatory phase are now showing clearer signs of operational execution, so security stakeholders should stay vigilant.


📌 Inside this Weekly Threat Shift

  1. The Shift of the Week #16

  2. Threat Signals

  3. The Information Battlefield

  4. Why It Matters

  5. Watchlist, Next 30 Days

  6. Strategic Consequence

  7. Final Analytical Line.


The Shift of the Week #16

From jihadist mobilisation and youth extremism to proxy violence and state-linked sabotage

Over recent months, many of the most important warning indicators have appeared before violence: reconnaissance, acquisition of weapons, extremist networking, testing of logistics routes, drone incursions and clandestine infrastructure. This week shows that these preparatory layers are delivering tangible operational results, so we need to stay vigilant.

Germany’s attribution of the Leipzig/Halle incident is the clearest example. The explosive-equipped drone discovered near Ukrainian Antonov cargo aircraft in August was initially treated cautiously, as it should have been. Now, the German government’s conclusion that Russia was responsible highlights a significant escalation and underscores the need for strategic awareness among security officials.

This matters because it represents an escalation in method as much as in target selection. European states have already confronted cyber intrusions, disinformation, suspicious fires, parcel bombs, reconnaissance operations and other forms of activity attributed or suspected to involve Russian services. An explosive drone directed toward a strategic logistics facility introduces a more overtly kinetic capability while still retaining many characteristics of hybrid warfare: deniability, limited footprint, ambiguous escalation thresholds and the use of technology capable of producing disproportionate disruption at relatively low cost.

NATO’s assessment during the same period is equally important. Alliance officials stated that Russian hybrid activity in Europe is increasing, while also stressing that there is currently no indication of an imminent conventional Russian attack against NATO territory. That distinction defines the problem. The most immediate confrontation with Russia is not necessarily occurring through tanks crossing an Alliance border. It is occurring in the space below conventional war, where sabotage, intelligence operations, drones and covert networks can impose costs without triggering an automatic military response.


Threat Signals

The jihadist threat produced a different but complementary indicator in Germany. Two German nationals, Edis Z. and Jiyan K., went on trial in Frankfurt over allegations that they prepared a serious act of violence associated with the Islamic State. Prosecutors allege that they intended to travel abroad to receive weapons training and die as “martyrs”. One of the defendants is additionally accused of having contemplated a suicide attack in Germany using either an explosive belt or a vehicle. Both were arrested at departure gates while allegedly attempting to travel towards the Middle East.

The analytical value of the case lies in the relationship between external mobilisation and domestic violence. The traditional foreign-fighter model is often understood as movement from Europe toward an overseas jihadist theatre. But training abroad and violence at home can exist within the same trajectory. The concern is not merely that individuals may reach a militant organisation. It is that contact with an organisation, battlefield environment or training network can increase capability before violence is redirected toward the country of origin.

This post is for paid subscribers

Already a paid subscriber? Sign in
© 2026 Daniele Garofalo Monitoring · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture