Skip to content
WatchGuard: Lower attack volumes mask quieter, more targeted threats

WatchGuard: Lower attack volumes mask quieter, more targeted threats

Iteuropa • September 23, 2026

WatchGuard has warned MSPs not to interpret a sharp fall in network attack volumes as an indication that cyber risk is declining, arguing that attackers are instead becoming quieter, more varied and increasingly reliant on legitimate credentials and tools.

The cybersecurity vendor’s latest Global Threat Report found network attack volumes fell 79% during the first half of 2026, while novel endpoint malware increased by more than 2,000% year-on-year. Almost 96% of endpoint threats appeared on only a single machine.

Corey Nachreiner, CISO at WatchGuard, said the fall in overall attack volumes was heavily influenced by the decline of two large-scale scanning campaigns rather than a broad retreat by cyber criminals.

A dotCMS vulnerability fell 89% and attacks exploiting a HAProxy header bypass dropped by more than 99%. At the same time, WatchGuard detected 410 unique exploits, up from 381, while the proportion of detections accounted for by the top ten signatures fell from 74% to 60%.

“Attackers did less this half. They did far more different things,” Nachreiner said.

He argued that an increasingly important part of this shift is attackers avoiding malware and exploits altogether, instead using stolen credentials and legitimate administrative tools. “If a threat actor holds valid credentials, they can use the tools already built into Windows, plus your own remote management and security software, to get in and stay in,” he said.

“It is much harder to tell a stolen identity using a legitimate tool from an administrator doing their job.”

Why do old vulnerabilities remain?

The report also found that the median vulnerability referenced by its top 50 network attack signatures dated from 2014, while 31 of 44 CVE-linked signatures targeted flaws at least a decade old.

Nachreiner said this should not automatically be interpreted as evidence that MSPs are failing to patch customer environments. “We don’t have empirical data on the why, but we have a strong hypothesis and our own numbers support it: most of this isn’t targeting at all. It’s automation with a very long memory.”

Automated scanning tools continue to carry exploit code for old vulnerabilities because it remains cheap, stable and effective against the relatively small number of systems that remain exposed. WatchGuard found, for example, that a generic web shell detection reached 75% of reporting Fireboxes in Belgium despite generating only 774 detections.

“Our rule of thumb is that reach without volume means everyone is being probed, and volume without reach means someone specific is being hunted,” Nachreiner said.

However, he highlighted ageing infrastructure as an area where MSPs should pay particular attention. WatchGuard continues to encounter Windows XP and Server 2003 systems in production, alongside legacy technology in sectors including banking, manufacturing and healthcare.

“If there is a real gap for the channel, it’s not patching, it’s end-of-life hardware,” he said. “A device nobody patches anymore isn’t a security control, it’s a permanent open door with a reassuring logo on it. That’s an inventory-and-retire conversation every MSP should be having this year.”

Attacks are not the same as breaches

Nachreiner also cautioned against treating security product telemetry as a measure of successful breaches. “Product telemetry is the alarm going off. It tells you which techniques attackers are leaning on and how that changes, which I’d argue is genuinely valuable for prioritising defences. It does not tell you what got through.”

WatchGuard’s ransomware tracking provides a closer indication of successful compromises. The company recorded 4,932 public extortion claims during the first half of 2026, alongside 41 newly identified ransomware groups.

Nachreiner said that contrast demonstrates why attack detections and breach data need to be considered separately. “Public extortion claims, meanwhile, eased slightly off a late-2025 spike but remain well above historical norms. Same landscape, two very different columns.”

“That is precisely your alarm-versus-burglary distinction, and it’s why I’d read the two datasets side by side rather than expecting one to explain the other.”

Extracted Entities

Attack Types (1)

Countries (1)

Platforms (1)