Endpoint Malware Surged as Network Attacks Declined
The H1 2026 Internet Security Report shows attackers shifting from broad network scanning to highly targeted malware.
Updated on Sept. 23, 2026 in Cybersecurity

Live Poll
Do you feel more concerned about targeted digital threats than you were in the past?
WatchGuard released its H1 2026 Internet Security Report, detailing a significant pivot in cyberattack methodology. Threat actors have moved away from broad network-based campaigns, instead favoring novel, highly specific endpoint malware.
Why it matters
This shift toward individual-specific threats, driven by automation and AI-assisted tooling, indicates that traditional perimeter defenses are becoming less effective against modern, tailored exploitation tactics.
Novel endpoint malware rose 2,065% year-on-year, with 96% of these threats appearing on only one machine. Meanwhile, 95% of malware arrived over TLS-encrypted connections, yet only 20% of deployed devices actively inspect that traffic.
The players
WatchGuard
A cybersecurity firm that provides network security appliances and endpoint protection solutions, known for publishing quarterly security research.
The details
Attackers are utilizing Malware-as-a-Service, automation, and AI-assisted tools to bypass traditional perimeter defenses by favoring low-and-slow probing and credential-based access. This shift targets individual victims rather than relying on high-volume scanning, which often uses outdated signatures with a median disclosure year of 2014. SQL injection remains a primary vector, accounting for over 17% of detected network attacks.
Timeline
2014 marked the median disclosure year for the top 50 network-attack signatures.
H2 2025 saw APAC network exploits account for 21% of activity.
H1 2026 is the period covered by the WatchGuard Internet Security Report.
The Tech Race
This report marks a definitive departure from the historical reliance on perimeter-based security and high-volume, generic network scanning. Security providers are currently in an arms race to develop automated, context-aware detection capabilities to counter threats that evade traditional signature-based filters.
Security administrators must prioritize TLS inspection, as only 20% of currently deployed devices are effectively monitoring encrypted traffic for hidden payloads. Organizations should also shift resources from perimeter-only defenses toward endpoint-specific detection, given that nearly all modern malware is now uniquely tailored per target.
The takeaway
The rise of individualized malware makes generic network monitoring insufficient for modern enterprise security. Security leaders should watch for the integration of AI-based endpoint inspection tools designed to catch single-machine, non-recurring threats.
Further reading
For broader analysis on how organizations are evolving their defensive posture, see our coverage in Cybersecurity.
Live Poll
Do you feel more concerned about targeted digital threats than you were in the past?






