WatchGuard's 1H 2026 Threat Report found endpoint ransomware detections down 68% year over year while public extortion claims neared 5,000, the most on record. The gap between the two numbers is AI-assisted precision that most defenses were never built to see.
Key Takeaways
A 68% drop in ransomware detections sounds like the best news the industry has had in years. According to WatchGuard's newly published 1H 2026 Threat Report, that is exactly the number, and it is exactly the wrong conclusion to draw from it. Public extortion claims are simultaneously on pace for a record year, 41 new ransomware groups surfaced in six months, and the top eight of them alone accounted for more than half of nearly 5,000 claims. Fewer alarms went off. The damage did not shrink to match.
WatchGuard's Chief Information Security Officer, Corey Nachreiner, put the disconnect plainly: "Attackers are not less dangerous because alert totals declined. They are using every tool at their disposal to become more selective and precise." The report backs that up with numbers that only make sense together. Network attack volume fell 79%, but novel malware on endpoints rose more than 2,000% year over year, and 96% of endpoint threats appeared on exactly one machine. That is not an industry under less pressure, it is an industry being hit by campaigns engineered to look like nothing rather than campaigns loud enough to count.
The delivery mechanism explains why signature-based tools keep missing it. Ninety-five percent of malware in the report travelled over encrypted TLS connections, and only 20% of devices actually inspect that traffic before it lands. Evasive malware, built specifically to slip past detection, still cleared 36% of devices running advanced defenses, and a third of the median vulnerabilities being actively exploited trace back to 2014, a decade-old weakness nobody expected to still matter. Attackers are not choosing between old tricks and new ones. They are running both.
Darktrace's State of AI Cybersecurity 2026 survey of more than 1,500 security professionals shows the human side of the same problem. Eighty-seven percent are seeing more AI-driven threats, 73% say those threats already have a significant organizational impact, and 87% say AI is directly increasing both malware sophistication and its success rate against them. None of that is contested internally: 92% agree AI-driven threats are forcing a defense upgrade now.
What has not moved is confidence. Forty-six percent of respondents still feel inadequately prepared for the current threat landscape, only a modest improvement on the 60% who said the same in 2024. Two years of vendor investment, board attention, and new tooling closed roughly a third of the preparedness gap and left the rest standing. Sixty-two percent of organizations reported a deepfake-based social engineering attempt, and a third of malicious emails observed in 2025 ran over 1,000 characters, a pattern consistent with large language model generation rather than a human writing on a deadline. The threats are not hypothetical anymore. The readiness still is.
Check Point's 2026 Cloud Security Report measures exactly where that gap sits inside an organization. Seventy-seven percent of respondents updated their cloud security strategy specifically for AI. Only 26% can actually enforce that updated policy consistently, a 51-point gap between what leadership decided and what the environment will actually let them do. Seventy-eight percent reported a confirmed or suspected AI-related security incident, 54% confirmed one outright, and 24% could not even say either way because they lack the visibility to tell.
The report ties the enforcement gap to architecture as much as intent. Only 24% of organizations can fully inspect AI traffic without a performance hit, 71% report a rise in web application firewall false positives as AI traffic volume grows, and 67% describe their policies as fragmented across environments, exactly the condition that lets a precisely targeted, TLS-encrypted, single-machine threat move without tripping anything at all.
Sixty-eight percent, 79%, 2,000%. Each of WatchGuard's numbers moves in the direction that should reassure a security team, and together they describe an industry under more pressure than it has faced in years. The organizations that will do well in the next twelve months are not the ones celebrating quieter dashboards. They are the ones asking why the dashboards went quiet.
Guide
A 68% drop in detections only helps if the signals you still catch are the right ones. This is the checklist for spotting ransomware before it reaches the stage a dashboard actually flags.
Download
Whitepaper
Check Point's own research found a 51-point gap between AI security policy and what teams can enforce. This blueprint is built to close that gap at the infrastructure layer.
Download
Report
Ninety-six percent of endpoint threats in WatchGuard's data hit exactly one machine, below the threshold most alerting is tuned for. This report covers what proactive hunting catches that waiting for an alert won't.
Download
A month earlier, one macOS flaw Apple had already fixed was still being used to plant cryptocurrency miners.
Moonlock Lab found unique malicious macOS samples up roughly 40% year over year, and that two stealer families now dominate detections.
Cisco Talos found phishing back on top for initial access, and CrowdStrike found most of what follows is now malware-free.