WatchGuard report finds network attack detections down 79% as novel malware rises

0

WatchGuard says network attack detections fell 79% in the first half of 2026, even as “novel” endpoint malware increased 2,065% year-on-year, according to its upcoming H1 2026 Internet Security Report.

The biannual report analyses attack data from WatchGuard’s global network of security appliances and endpoints. WatchGuard says the results indicate attackers are moving away from high-volume campaigns and towards more targeted activity.

In regional findings highlighted ahead of the report’s release, WatchGuard said the Asia-Pacific region accounted for 50.33% of per-Firebox network malware detections—about double the levels seen in Europe, the Middle East and Africa (EMEA) and the Americas (AMER). The company said APAC also overtook the Americas as the most-attacked region for network exploits.

For Australia, WatchGuard said a Mirai botnet variant was detected on 14.21% of Fireboxes, which it described as the third-highest rate of any country worldwide.

WatchGuard attributed the shift in activity in part to Malware-as-a-Service, automation and AI-assisted tooling, which it said can help attackers generate victim-specific malware at scale and bypass traditional controls.

Additional findings cited from the report include high levels of encrypted malware delivery and limited inspection of encrypted traffic. WatchGuard said 95% of malware was delivered over TLS, while only 20% of deployed devices inspected encrypted traffic.

The report also points to older vulnerabilities continuing to be exploited. WatchGuard said the median vulnerability targeted by the top 50 network attack signatures dated back to 2014.

WatchGuard said credential-based techniques appeared prominently in threat hunting data, including credential access, persistence and defence evasion. It also said ransomware remained active, tracking 41 new ransomware groups in H1 2026.

Overall, WatchGuard said the data suggests reduced attack volumes do not necessarily translate to lower risk, and that attacker activity may be becoming more selective and evasive, particularly in APAC.

You can read the full report here.

Share.