Sydney, Australia – Cyber attackers are increasingly using AI-assisted tools and automation to shift from high-volume campaigns to more targeted malware, broader probing, and credential-based access, according to WatchGuard Technologies’ latest report.
The report, covering the first half of 2026, found that overall network exploit activity fell by 79%, while novel malware increased by more than 2,000% year on year on endpoints. Nearly 96% of endpoint threats detected during the period appeared on only one machine.
Based on anonymised, aggregated threat intelligence from WatchGuard’s network and endpoint security products, the findings suggest that lower attack volumes do not necessarily mean reduced threat activity. Instead, attackers may be testing more vulnerabilities across networks and developing payloads tailored to individual systems.
“Attackers are not less dangerous because alert totals declined. They are using every tool at their disposal to become more selective and precise,” said Corey Nachreiner, Chief Information Security Officer at WatchGuard.
“The recent findings show a shift from reusable payloads and high-volume scanning to malware tailored for individual systems, broad low-and-slow probing and credential-based access that can go around perimeter defences. For MSPs, that makes unified visibility, TLS inspection, AI-powered detection, strong identity controls, and continuous response essential to protecting customers at scale,” Nachreiner continued.
Attack techniques and network activity evolve
The report identified a shift in initial-access techniques, with attackers increasingly using trusted accounts and native tools to navigate security layers. PowerShell detections declined sharply, while credential access, persistence, remote access and defence evasion emerged as prominent threat-hunting themes.
Although average network attack volumes decreased, the number of unique intrusion prevention system (IPS) signatures increased, and the top 10 attacks accounted for a smaller share of overall activity.
A generic web-shell signature was the most widespread network attack identified in the report, reaching 75% of machines in Belgium and nearly 60% in Italy and the United States.
The findings also highlighted the continued use of older vulnerabilities. The median disclosure year for vulnerabilities referenced by the top 50 network-attack signatures was 2014, while 31 of the 44 signatures referencing CVEs targeted flaws that were at least a decade old. SQL injection accounted for more than 17% of network-attack detections.
Encrypted traffic and evasive malware
The report found that 95% of malware was delivered over Transport Layer Security (TLS), although only 20% of deployed devices inspected encrypted traffic.
Evasive malware accounted for nearly one-third of detections overall. It represented 36% of detections observed through TLS inspection on devices using advanced malware defences.
The figures highlight a potential visibility gap for organisations that do not inspect encrypted traffic, as malicious activity may otherwise be harder to identify.
Ransomware activity remains varied
Endpoint ransomware detections fell by more than 68% year-on-year, despite public extortion activity reaching record levels, according to WatchGuard.
The company tracked 41 new ransomware groups during the first half of 2026. The eight largest groups accounted for more than half of nearly 5,000 public extortion claims recorded during the period.
WatchGuard described the ransomware ecosystem as both consolidating and attracting new entrants, indicating continued activity despite the decline in endpoint detections.
Recommendations for security teams
The report recommends layered security measures that combine intrusion prevention, advanced endpoint protection, identity security, and continuous monitoring.
It also advises security teams and managed service providers to prioritise older vulnerabilities and unsupported edge devices, implement multi-factor authentication (MFA) and zero-trust access controls, and assess attack reach and diversity alongside overall alert volumes.

