The report, compiled from anonymised threat intelligence gathered by WatchGuard’s network and endpoint security appliances, found that almost 96% of endpoint threats were observed on a single device, underscoring a move toward bespoke payloads rather than reusable, mass‑distributed malware.
Network‑level detections fell 79% in the first half of 2026, yet novel endpoint malware surged 2,065% year‑on‑year, indicating attackers are abandoning high‑volume scanning in favour of low‑and‑slow probing and credential‑based intrusion.
WatchGuard attributes the shift to the rise of Malware‑as‑a‑Service platforms, automation and AI‑assisted tooling that let threat actors test many vulnerabilities, generate distinct payloads at scale and evade traditional defenses.
Chief Information Security Officer Corey Nachreiner warned that the drop in alert volume should not be taken as a sign of reduced risk, saying attackers are becoming “more selective and precise” and that unified visibility, TLS inspection and AI‑driven detection are now essential for managed service providers.
The Asia‑Pacific region bore the brunt of the change, accounting for 50.33% of detections on WatchGuard’s Firebox devices—roughly double the share in EMEA and the Americas—and saw network exploit activity rise from 21% to 38.31% compared with H2 2025.
Australia ranked third globally for Mirai botnet activity, with the variant detected on 14.21% of Australian Fireboxes, while Oceania joined Africa and Southeast Asia among the top three regions for endpoint threats.
Older vulnerabilities remain a fertile hunting ground: the median vulnerability among the top 50 network‑attack signatures dates back to 2014, and 31 of 44 CVE‑referenced signatures target flaws at least a decade old, with SQL injection alone responsible for over 17% of network‑attack detections.
Encrypted traffic continues to be a major delivery vector, with 95% of malware arriving over TLS, yet only about 20% of deployed WatchGuard devices inspect encrypted streams, leaving a large portion of malicious activity hidden.
Ransomware activity persisted despite a 68% drop in endpoint detections; the firm tracked 41 new ransomware groups in H1 2026, with the eight largest accounting for more than half of nearly 5,000 public extortion claims, suggesting consolidation among operators while still attracting newcomers.
The report concludes that raw alert counts are becoming a weaker indicator of risk, and that factors such as attack diversity, credential abuse, exposure to legacy flaws and visibility into encrypted traffic will drive security priorities for MSPs and enterprise teams moving forward.