Industry NewsAI Business & Ecosystem
WatchGuard report finds AI-assisted shift from mass malware to precision cyberattacks

Article content
Cyberattacks may be becoming quieter, but they are not necessarily becoming less dangerous.
WatchGuard's H1 2026 Global Threat Report points to a significant change in how threat actors are operating. While the overall volume of network attacks declined by 79%, novel endpoint malware increased by more than 2,000% year over year.
The report, based on anonymised and aggregated threat intelligence from WatchGuard's network and endpoint security products, suggests attackers are moving away from noisy, high-volume campaigns toward more targeted malware, low-intensity probing, credential-based access and techniques designed to evade traditional security controls.
Lower attack volume does not mean lower risk
One of the report's most notable findings is the widening gap between attack volume and attack diversity.
WatchGuard found that nearly 96% of endpoint threats appeared on exactly one machine during the analysed period. The company says this pattern, combined with the rise in novel malware, indicates that attackers are using automation, Malware-as-a-Service and AI-assisted tooling to create more customised attacks at scale.
That changes the way organisations need to interpret security telemetry. A decline in the number of alerts does not necessarily indicate that the threat environment is improving.
Instead, attacks can become harder to detect when adversaries rely on unique payloads, legitimate tools and compromised credentials rather than reusable malware campaigns.
AI is changing the attacker's playbook
WatchGuard says AI-assisted tooling is helping threat actors accelerate the development of victim-specific malware and test vulnerabilities across a broader range of networks.
At the same time, attackers are increasingly relying on trusted accounts and native tools to move through environments.
The report identifies credential access, persistence, remote access and defence evasion among the prominent threat-hunting themes during the first half of 2026, while PowerShell detections declined sharply.
This reflects a broader evolution in the attack surface. Instead of relying solely on malicious files or obvious exploits, attackers can use legitimate credentials and tools that already exist within an organisation's environment.
APAC emerges as a major threat hotspot
The report also highlights significant regional differences.
APAC accounted for 50.33% of network malware detections per Firebox, roughly twice the share attributed to EMEA and the Americas.
The region also saw its share of network exploits increase from 21% in H2 2025 to 38.31% in H1 2026, making APAC the most-attacked region for network exploits in the report.
Australia also featured prominently, ranking third globally for Mirai activity, with the variant detected on 14.21% of Australian Fireboxes.
Oceania was additionally among the top three regions for endpoint threats, alongside Africa and Southeast Asia.
Attackers are probing more quietly
The decline in average network attacks masks another important trend: attackers are spreading activity across a wider range of signatures.
WatchGuard found that unique IPS signatures increased even as average attack volume fell, while the top 10 attacks represented a smaller share of overall activity.
A generic web-shell signature became the world's most widespread network attack, reaching 75% of machines in Belgium and nearly 60% in Italy and the United States.
For security teams, the implication is that focusing only on the highest-volume alerts may leave broader, lower-intensity activity unnoticed.
Old vulnerabilities remain effective
The report also highlights how attackers continue to exploit vulnerabilities that organisations have known about for years.
The median vulnerability referenced by WatchGuard's top 50 network-attack signatures was disclosed in 2014, while 31 of 44 CVE-referenced signatures targeted vulnerabilities that were at least a decade old.
SQL injection alone accounted for more than 17% of network-attack detections.
The findings reinforce that attackers do not necessarily need a new vulnerability when older weaknesses remain exposed across enterprise environments.
Encrypted traffic creates another visibility gap
Encryption continues to provide another avenue for attackers to hide malicious activity.
WatchGuard found that 95% of malware arrived over TLS, while only 20% of deployed devices inspected encrypted traffic.
Evasive malware accounted for nearly one-third of detections overall and 36% of detections observed through TLS inspection on devices using advanced malware defences.
For organisations, this creates a difficult balance between maintaining privacy and performance while ensuring that encrypted traffic does not become a blind spot for security teams.
Ransomware remains an active ecosystem
Ransomware activity also continues to evolve.
While endpoint ransomware detections declined by more than 68% year over year, WatchGuard tracked 41 new ransomware groups during H1 2026.
The company also recorded nearly 5,000 public extortion claims, with the eight largest groups accounting for more than half of those claims.
The figures point to an ecosystem that is simultaneously consolidating around established groups while continuing to attract new operators.
A broader view of cybersecurity risk
Taken together, WatchGuard's findings suggest that cybersecurity teams need to look beyond raw alert volumes when assessing their exposure.
The threat landscape is increasingly shaped by identity compromise, encrypted traffic, unique malware, low-intensity probing and vulnerabilities that remain unpatched for years.
WatchGuard says organisations and managed service providers should prioritise layered protection across network, endpoint and identity environments, alongside MFA, Zero Trust access controls, continuous monitoring and greater visibility into encrypted traffic.
The larger takeaway is straightforward: fewer alerts do not necessarily mean fewer threats.
As attackers become more selective and increasingly use automation and AI to customise their techniques, security teams may need to pay as much attention to the diversity, reach and behaviour of attacks as they do to their overall volume.
About WatchGuard Technologies
WatchGuard Technologies is a global cybersecurity company focused on managed service providers. Its Unified Security Platform brings together network, endpoint and identity security to help MSPs simplify security operations and protect customers at scale. WatchGuard says more than 25,000 MSPs use its technologies to protect more than 1.5 million customers worldwide.
Source and Credits
WatchGuard Technologies, H1 2026 Global Threat Report / Hotwire AU