IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
WatchGuard warns of shift to targeted cyberattacks

WatchGuard warns of shift to targeted cyberattacks

Wed, 23rd Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

WatchGuard has released its H1 2026 Internet Security Report, which points to a shift towards more targeted cyberattacks.

Network attack detections fell 79%, while novel endpoint malware rose 2,065% year on year. Based on anonymised, aggregated threat intelligence from WatchGuard's network and endpoint security products, the report found that almost 96% of endpoint threats in the period appeared on exactly one machine.

The contrast suggests attackers are moving away from broad, repeatable campaigns towards malware tailored to individual victims. According to WatchGuard, Malware-as-a-Service, automation and AI-assisted tooling are helping threat actors test more vulnerabilities, generate distinct payloads at scale and evade established security controls.

Corey Nachreiner, Chief Information Security Officer at WatchGuard, cautioned that the drop in alert volumes should not be mistaken for lower risk.

"Attackers are not less dangerous because alert totals declined. They are using every tool at their disposal to become more selective and precise," said Corey Nachreiner, Chief Information Security Officer at WatchGuard.

He said the change reflects a broader shift in attacker methods.

"The recent findings show a shift from reusable payloads and high-volume scanning to malware tailored for individual systems, broad low-and-slow probing and credential-based access that can go around perimeter defenses. For MSPs, that makes unified visibility, TLS inspection, AI-powered detection, strong identity controls, and continuous response essential to protecting customers at scale," said Nachreiner.

Regional picture

In Asia-Pacific, the data showed a heavier burden of network malware than in other regions. APAC accounted for 50.33% of detections per Firebox, roughly double the level recorded in EMEA and the Americas.

The region also became the most attacked for network exploits in the half, rising from 21% in H2 2025 to 38.31% in H1 2026. Within that picture, Australia ranked third globally for Mirai activity, with the botnet variant detected on 14.21% of Australian Fireboxes.

Oceania also ranked among the top three regions for endpoint threats, alongside Africa and Southeast Asia. The figures suggest the region is exposed both to network-level exploitation and more localised malware activity on devices.

Older flaws

One finding was the continued use of long-known vulnerabilities. The median vulnerability referenced by the top 50 network-attack signatures was disclosed in 2014, while 31 of 44 CVE-referenced signatures targeted flaws at least a decade old.

SQL injection alone accounted for more than 17% of network-attack detections. This points to continued attacker reliance on weaknesses that remain unpatched or persist in unsupported systems.

The report also found a shift in the balance of initial-access techniques. PowerShell detections declined sharply, while credential access, persistence, remote access and defence evasion became the main threat-hunting themes in the first half.

At the same time, quieter network conditions did not mean less scanning. Average network attacks declined, but unique intrusion prevention signatures increased, and the top 10 attacks accounted for a smaller share of total activity, indicating broader probing across a wider range of techniques.

A generic web-shell signature emerged as the most widespread network attack in the data. It reached 75% of machines in Belgium and almost 60% in Italy and the United States, showing how low-intensity but widely distributed activity can spread across very different markets.

Encrypted traffic

Encrypted traffic remained a major delivery route for malware. WatchGuard said 95% of malware arrived over TLS, but only 20% of deployed devices inspect encrypted traffic.

Evasive malware represented nearly one-third of detections overall and 36% of detections observed through TLS inspection on devices using advanced malware defences. That gap indicates large volumes of malicious activity may remain hidden where encrypted traffic is not inspected.

Ransomware, meanwhile, remained active despite a decline in endpoint detections. Endpoint ransomware detections were down more than 68% year on year, even as public extortion activity reached record levels.

WatchGuard tracked 41 new ransomware groups in the first half of the year, and the top eight accounted for more than half of nearly 5,000 public extortion claims. The figures suggest the market is both concentrating around larger operators and still attracting new entrants.

For managed service providers and security teams, the report argued that raw alert volume alone is becoming a weaker guide to risk. Attack reach, attack diversity, credential abuse, exposure to older vulnerabilities and visibility into encrypted traffic are becoming more important as attackers use quieter methods to reach targets.