Endpoint Malware Surged as Network Attacks Declined

The H1 2026 Internet Security Report shows attackers shifting from broad network scanning to highly targeted malware.

Updated on Sept. 23, 2026 in Cybersecurity

Bold flat-color editorial illustration in navy and cream showing a single wire node breaching a geometric lattice structure.
Threat actors are increasingly bypassing traditional perimeter defenses by shifting focus toward highly targeted endpoint malware rather than high-volume network scanning. AI Illustration. Upload story photo >

Live Poll

Do you feel more concerned about targeted digital threats than you were in the past?

WatchGuard released its H1 2026 Internet Security Report, detailing a significant pivot in cyberattack methodology. Threat actors have moved away from broad network-based campaigns, instead favoring novel, highly specific endpoint malware.

Why it matters

This shift toward individual-specific threats, driven by automation and AI-assisted tooling, indicates that traditional perimeter defenses are becoming less effective against modern, tailored exploitation tactics.

Novel endpoint malware rose 2,065% year-on-year, with 96% of these threats appearing on only one machine. Meanwhile, 95% of malware arrived over TLS-encrypted connections, yet only 20% of deployed devices actively inspect that traffic.

The players

WatchGuard

A cybersecurity firm that provides network security appliances and endpoint protection solutions, known for publishing quarterly security research.

The details

Attackers are utilizing Malware-as-a-Service, automation, and AI-assisted tools to bypass traditional perimeter defenses by favoring low-and-slow probing and credential-based access. This shift targets individual victims rather than relying on high-volume scanning, which often uses outdated signatures with a median disclosure year of 2014. SQL injection remains a primary vector, accounting for over 17% of detected network attacks.

Timeline

  1. 2014 marked the median disclosure year for the top 50 network-attack signatures.

  2. H2 2025 saw APAC network exploits account for 21% of activity.

  3. H1 2026 is the period covered by the WatchGuard Internet Security Report.

The Tech Race

This report marks a definitive departure from the historical reliance on perimeter-based security and high-volume, generic network scanning. Security providers are currently in an arms race to develop automated, context-aware detection capabilities to counter threats that evade traditional signature-based filters.

Security administrators must prioritize TLS inspection, as only 20% of currently deployed devices are effectively monitoring encrypted traffic for hidden payloads. Organizations should also shift resources from perimeter-only defenses toward endpoint-specific detection, given that nearly all modern malware is now uniquely tailored per target.

The takeaway

The rise of individualized malware makes generic network monitoring insufficient for modern enterprise security. Security leaders should watch for the integration of AI-based endpoint inspection tools designed to catch single-machine, non-recurring threats.

Further reading

For broader analysis on how organizations are evolving their defensive posture, see our coverage in Cybersecurity.

Live Poll

Do you feel more concerned about targeted digital threats than you were in the past?