WatchGuard: nearly all endpoint malware now hits one machine only — and 95% arrives over TLS
WatchGuard's 1H 2026 threat report, out September 22, says novel endpoint malware rose over 2,000% year-over-year while only 20% of devices inspect the encrypted traffic it arrives in.
On September 22, 2026, WatchGuard's Threat Lab published its threat report for the first half of 2026. Two numbers stand out: nearly 96% of the malware its endpoint products caught was seen on exactly one machine, and 95% of malware arrived inside encrypted TLS connections — while only 20% of deployed devices inspect that encrypted traffic. If your organisation runs a firewall with HTTPS inspection switched off and relies mainly on signature-based antivirus, this report is an argument for revisiting both.
What happened, in plain English
WatchGuard is a network and endpoint security vendor. Twice a year its research group, the Threat Lab, publishes aggregated, anonymised statistics from the firewalls and endpoint agents its customers run. The edition released on September 22, 2026 covers January to June 2026.
The headline finding is a change of shape rather than a change of volume. Network attack detections fell 79% compared with the same period a year earlier. Endpoint ransomware detections fell more than 68%. On the face of it, that sounds like good news. It is not, because over the same period the amount of novel malware — samples the vendor had never seen before — rose by more than 2,000% year-over-year on endpoints, and public extortion activity hit record levels even as ransomware detections dropped.
The single most telling statistic is that nearly 96% of endpoint threats showed up on exactly one machine. In other words, almost every malicious file was a one-off, built or mutated for a single target.
That matters because of how a lot of security tooling still works. Traditional antivirus recognises malware the way a bouncer recognises a banned customer from a photograph: it compares what it sees against a list of known-bad files, identified by a fingerprint called a signature (a hash or pattern that uniquely identifies a file). This approach works well when the same malicious file is mailed to thousands of organisations, because once one victim reports it, everyone else is protected. It works poorly when every victim receives a file nobody has ever seen.
Two more terms worth defining. TLS (Transport Layer Security) is the encryption behind the padlock in your browser — the "S" in HTTPS. TLS inspection, sometimes called HTTPS inspection or SSL decryption, is a firewall feature that decrypts traffic, scans it, and re-encrypts it, so malware hidden inside an encrypted download can be caught in transit. WatchGuard says 95% of the malware it saw arrived over TLS, but only about 20% of the devices in its telemetry had inspection enabled. Most organisations are, in effect, scanning the one-fifth of the road where the lights are on.
WatchGuard's own framing for why payloads have become unique is AI tooling in the hands of attackers — generating or rewriting each sample so it does not match anything on file. That is the vendor's interpretation, and it is worth treating as a hypothesis rather than a measurement; see the expert view below.
Are you affected? What to do now
This is a trend report, not a vulnerability disclosure. There is no CVE identifier, no patch, and no indicator of compromise to hunt for — WatchGuard published none, and you should be sceptical of anyone offering IOCs "from" this report. What it gives you is a reason to check a handful of settings you may not have looked at in a while. None of this is urgent today; all of it is worth putting on a quarterly review.
- Check whether HTTPS/TLS inspection is enabled on your perimeter. On most firewalls this is off by default. Confirm the actual running configuration rather than the policy document — they drift apart.
- If it is off, find out why. The usual reasons are genuine: certificate pinning breaks some applications, privacy or works-council rules may restrict it, and there is a real performance cost. A partial rollout — inspecting general web browsing while excluding banking, healthcare and HR categories — is a normal compromise and much better than nothing.
- Verify your endpoint protection does behavioural detection, not just signatures. Ask your vendor directly: what proportion of your detections come from behaviour, heuristics or machine learning rather than known-file matching? If your product is signature-only, the 96%-unique figure is a direct argument for replacing it.
- Do not read falling ransomware detections as falling ransomware risk. WatchGuard tracked 41 new ransomware groups in the first half of 2026, and the top eight groups accounted for more than half of nearly 5,000 public extortion claims. Test your backup restores and your incident response plan on the normal schedule.
- Patch old things. One of the report's quieter findings is that the median vulnerability targeted by its top 50 network attack signatures was disclosed in 2014, and 31 of 44 CVE-referenced signatures targeted flaws at least a decade old. SQL injection alone accounted for more than 17% of network attack detections. Whatever attackers are doing with AI, they are still walking through doors that have been open for ten years.
- If you are a small organisation with a managed provider, the useful action is one email: ask whether TLS inspection is enabled on your firewall and what your endpoint product does when it meets a file it has never seen.
If you already run TLS inspection and a modern endpoint detection and response (EDR) product, and you patch, this report largely confirms you are pointed the right way. There is nothing to do today.
The expert view
Strip away the vendor framing and the substantive claim is about detection economics. Signature-based defence is a shared-cost model: one organisation pays the price of being patient zero, everybody else gets the protection for free. Per-target payload generation breaks that model by making the marginal cost of a unique sample approach zero for the attacker while leaving the defender's cost of first-sighting unchanged. That dynamic does not require AI — polymorphic and metamorphic malware, crypters and packers have produced unique-per-victim hashes since the 1990s — but generative tooling plausibly lowers the skill floor and raises the quality of the variation beyond what a packer produces.
So how much of this is genuinely new? The honest answer is that the 96% figure demonstrates uniqueness, not authorship. WatchGuard's telemetry can show that a sample was seen once; it cannot show that a model wrote it. The attribution to AI tooling is inference, and the report is a vendor publication drawn from one vendor's installed base — skewed towards small and mid-sized businesses and managed service providers, and towards organisations that bought this particular product. Treat the direction as more reliable than the magnitude.
Where independent primary evidence does exist, it supports the direction. Google Threat Intelligence Group's AI threat report of May 11, 2026 documented named malware families using a model API at runtime to rewrite themselves — PROMPTFLUX and HONESTCUE among them — and described AI-generated filler code in families it tracks as CANFAIL and LONGSTREAM, one of which queries the system's daylight-saving status 32 times purely to look busy. Anthropic's September 2026 threat intelligence report described state-linked and criminal operations automating large parts of their workflow. Separately, on the same day as the WatchGuard report, Gartner presented survey findings at its Security & Risk Management Summit in London — 297 senior security leaders surveyed between March and May 2026, of whom 41% reported deepfake incidents on audio calls — as reported by Infosecurity Magazine and Help Net Security; Gartner's own release was not publicly accessible at the time of writing.
The TLS number is the part of this report a practitioner should act on, and it is also the least novel. That 95% of malware arrives encrypted is unremarkable — nearly all web traffic is encrypted now. That only a fifth of devices inspect it is a long-standing gap with well-understood causes, and it is the one finding here where the fix is concrete, the cost is known, and the benefit does not depend on believing anything about AI.
What remains unknown: how much of the novel-sample surge is model-generated versus conventional repacking, whether the fall in network attack detections reflects fewer attacks or attacks that moved inside encrypted channels the sensors cannot see, and whether the ransomware detection drop is a real decline or a measurement artefact of the same encryption blind spot. WatchGuard has not published the underlying dataset, so these are not currently answerable from outside.
Official sources
- WatchGuard — "New WatchGuard Threat Report Reveals AI Tooling Underpins Tactical Shift from High-Volume Malware Campaigns to Precision Attacks in 1H 2026" (September 22, 2026) — the company's official announcement and the source of every WatchGuard figure above
- WatchGuard Threat Lab — Internet Security Report / Global Threat Report hub — where the full report is published
- Google Cloud Blog — Google Threat Intelligence Group, "Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access" (May 11, 2026) — primary evidence for self-modifying and AI-assisted malware families
- Anthropic — "Countering misuse of AI: September 2026" threat intelligence report — case studies of AI-automated intrusion operations
- Coverage: Infosecurity Magazine — "CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes" (September 22, 2026) — the Gartner summit figures cited above
- Coverage: Help Net Security — "The latest deepfake numbers give CISOs plenty to worry about" (September 22, 2026)