WatchGuard Technologies has released the conclusions of its latest Global Threat Report study. The semi-annual report reveals that threat actors are leveraging AI-assisted tools to quickly transition from massive, easily detectable campaigns to victim-specific malware, broader, low-intensity probes, and credential-based access.

Based on anonymized and aggregated threat intelligence from WatchGuard’s network and endpoint security products, the report shows that attackers are using increasingly sophisticated malware while overall network vulnerability exploitation activity decreases.

While total network attack volume fell 79%, new malware increased more than 2,000% year-over-year on endpoints, and nearly 96% of endpoint threats detected during the reporting period appeared on exactly one computer. These divergent signals indicate that threat actors are using Malware-as-a-Service, automation, and AI to test a greater number of vulnerabilities across more networks, create unique payloads for specific victims at scale, and bypass traditional controls.

Malware tailored to individual systems

“Attackers are no less dangerous because the number of alerts has decreased. They are using every tool at their disposal to be more selective and precise in creating malware,” explains Corey Nachreiner, CISO at WatchGuard. “The latest data shows a shift from reusable malicious payloads and mass scans toward malware tailored to individual systems, broad, sustained, low-intensity probes, and credential-based access capable of bypassing perimeter defenses. For MSPs, this makes unified visibility, TLS inspection, AI-based detection, rigorous identity checks, and continuous response essential to protecting customers at scale.”

In addition to the growing gap between the volume and diversity of attacks, key findings from the report also include:

· Changes in initial access techniques: Data shows that threat actors are increasingly using trusted accounts and native tools to navigate between different layers of security. Detections related to PowerShell decreased sharply, while credential access, persistence, remote access, and defense evasion became the most prominent topics in threat hunting during the first half of the year.

· Networks, while seeing less activity, are being surveyed more broadly: while the average number of network attacks decreased, the number of unique IPS signatures increased, and the top 10 attacks accounted for a smaller proportion of total activity. A generic web shell signature became the most widespread network attack in the world, hitting 75% of computers in Belgium and nearly 60% in Italy and the United States.

· Attackers continue to exploit old vulnerabilities: The median vulnerability referenced by the report’s top 50 network attack signatures was disclosed in 2014, and 31 of the 44 CVE-referenced signatures focused on flaws that are at least a decade old. SQL injections alone accounted for more than 17% of network attack detections.

· Encryption remains the default distribution path: 95% of malware arrived via TLS, but only 20% of deployed devices inspect encrypted traffic. Evasive malware accounted for nearly a third of total detections and 36% of detections observed using TLS inspection on devices using advanced malware defenses.

· Ransomware remains an active and highly competitive economy: the ransomware ecosystem is consolidating while continuing to attract new players. Endpoint detections fell more than 68% year-over-year, despite public extortion activity reaching record levels. WatchGuard identified 41 new ransomware groups in the first half of 2026, with the top eight accounting for more than half of the nearly 5,000 public extortion claims.

The findings reinforce the need for layered defenses that combine intrusion prevention, advanced endpoint protection, identity security, and continuous monitoring.

Security teams and MSPs should also prioritize older vulnerabilities and unsupported edge devices, apply MFA and Zero Trust access controls, and measure both the scope and diversity of attacks and the raw volume of alerts. Download a copy of the WatchGuard Global Threat Report and learn how WatchGuard helps MSPs defend against the latest threats.