WatchGuard: AI and Automation Drive a Shift to Targeted Cyberattacks

Network attacks fell 79% during the first half of 2026, but that drop in volume hasn’t meant less variety in threats. WatchGuard Technologies’ latest global report finds a more than 2,000% year-over-year increase in new malware on the endpoints it analyzed, and points to automation, Malware-as-a-Service (MaaS), and AI-assisted tools as part of a shift toward more targeted attacks.

AI-driven threats in 20 seconds

  • WatchGuard logged 79% fewer network attacks, but more variety in threats.
  • New malware grew more than 2,000% year-over-year on endpoints.
  • Nearly 96% of endpoint threats appeared on just a single machine.
  • 95% of malware arrived over TLS traffic, but only 20% of devices inspected it.
  • WatchGuard identified 41 new ransomware groups during the first half of the year.

The data comes from anonymized, aggregated threat intelligence drawn from WatchGuard’s network and endpoint security products. The company reads the gap between the drop in recorded attacks and the rise in diversity as a sign that attackers are relying less on high-volume campaigns and more on payloads tailored to specific victims.

That hypothesis fits with a combination of tools that automate tasks that used to take more manual work. WatchGuard points to the combined use of AI, on-demand malware services, and automation to probe more vulnerabilities across more networks and generate different payloads depending on the target.

The most striking figure is on the endpoint side. The more than 2,000% year-over-year growth in new malware stands in contrast to the drop in network attacks. On top of that, nearly 96% of the threats detected on endpoints appeared on exactly one machine during the period analyzed. Such a scattered distribution makes it harder to spot patterns from repeated campaigns and can reduce the effectiveness of certain signature-based defenses.

Attackers lean more on legitimate accounts and tools

The report also identifies shifts in the techniques used to gain and maintain initial access. PowerShell-related detections dropped sharply, while credential access, persistence, remote access, and defense evasion gained ground among the top threat-research topics during the first six months of the year.

Using legitimate accounts and tools that are already part of corporate systems lets malicious activity blend in with normal user or administrator actions. That shifts part of the detection effort away from looking for known malicious files and toward analyzing identities, behaviors, and relationships between events.

The report also found greater diversity in network attacks. While the average volume of attacks fell, the number of distinct intrusion prevention system (IPS) signatures triggered went up. At the same time, the ten most common attack techniques accounted for a smaller share of the total.

Among the most widespread signatures was a generic one tied to web shells, tools that can let an attacker maintain access or run commands through a compromised server. WatchGuard says this signature reached 75% of the machines analyzed in Belgium and nearly 60% in both Italy and the United States.

The report also notes that attackers keep exploiting old vulnerabilities. The median vulnerability tied to the 50 most common network attack signatures was disclosed back in 2014. Of the 44 signatures referencing CVE identifiers, 31 pointed to flaws at least a decade old.

SQL injection, a technique used to manipulate database queries through attacker-controlled input, accounted on its own for more than 17% of network attack detections.

Encrypted traffic makes it harder to see what reaches devices

Another finding in the report concerns encrypted traffic. WatchGuard estimates that 95% of malware arrived over TLS, the protocol used to protect much of the web traffic and other internet services.

However, only 20% of deployed devices inspected encrypted traffic. That gap leaves a significant share of communications outside the content analysis that certain security tools can perform.

The company also identifies evasive malware in nearly a third of total detections. Among devices using advanced malware defenses combined with TLS inspection, this type of threat accounted for 36% of detections observed.

None of this means every uninspected TLS stream is malicious, nor that inspection catches every threat. What it does show, according to the report, is a gap between the volume of traffic arriving encrypted and the capacity deployed to analyze it.

For managed service providers (MSPs), who handle security for multiple organizations, WatchGuard recommends a strategy that combines intrusion prevention, advanced endpoint protection, identity security, and ongoing research. It also recommends paying attention to older or unsupported devices, applying multi-factor authentication (MFA), and using access controls based on the Zero Trust model.

Ransomware drops on endpoints as new groups emerge

Ransomware follows a different dynamic. Endpoint detections fell more than 68% year-over-year during the period analyzed, while public extortion activity hit record levels according to the indicators WatchGuard tracks. This mirrors a pattern WatchGuard flagged a year earlier, when it reported malware bypassing 71% of signatures and network detections growing 171%.

The company identified 41 new ransomware groups during the first half of 2026. At the same time, the eight most active groups accounted for more than half of the nearly 5,000 public extortion claims recorded.

Taken together, this points to a ransomware market with established groups alongside new entrants. The drop in endpoint detections alone doesn’t mean the problem has gone away, especially when other indicators used to track extortion activity show a different trend.

The shift WatchGuard describes also changes how risk should be measured. A drop in overall alerts can mask more scattered activity if attackers generate different payloads, use valid credentials, or maintain a low-intensity presence for longer periods.

That’s why the report recommends organizations not measure their exposure solely by raw alert counts. The variety of techniques, the scope of attacks, compromised identities, exploited vulnerabilities, and the capacity to inspect encrypted traffic all provide other signals for assessing what’s happening inside a network.

The report’s central argument is that artificial intelligence doesn’t eliminate the need for known techniques or replace old vulnerabilities. Its usefulness for attackers also lies in making it easier to adapt and automate processes, which can make a threat less visible in terms of volume but more specific to each target.

Frequently asked questions

How much did network attacks drop in the first half of 2026?

WatchGuard recorded a 79% drop in the total volume of network attacks analyzed.

How much did new malware increase?

New malware grew more than 2,000% year-over-year on the endpoints WatchGuard analyzed.

What percentage of malware arrived over TLS?

95% of recorded malware arrived over TLS traffic, while only 20% of deployed devices inspected encrypted communications.

How many new ransomware groups did WatchGuard identify?

The company identified 41 new ransomware groups during the first half of 2026.

Scroll to Top