Blog de WatchGuard

Attackers Have Changed Their Playbook. Has Your Security Strategy Changed With Them?

Attackers now rely on stolen identities, encrypted traffic, and stealth tactics. Learn how WatchGuard helps MSPs detect, prevent, and respond.

Cybersecurity teams have spent years preparing for malware, ransomware, and high-volume attacks. Yet the latest WatchGuard Global Threat Report reveals a more nuanced and potentially more dangerous reality: attackers are becoming quieter, more evasive, and increasingly reliant on stolen credentials, legitimate tools, encrypted communications, and long-known vulnerabilities.

For MSPs and IT leaders, the challenge isn't simply understanding these trends. It's ensuring their security architecture is designed to stop them.

Threat Trend: Identity Has Become the New Attack Surface

One of the most significant findings in the report is the shift in initial access techniques. Rather than relying on traditional malware, threat actors are increasingly using compromised credentials, persistence mechanisms, remote access tools, and defense evasion techniques to move through environments undetected.

This reflects a fundamental change in attacker behavior. If cybercriminals can log in using legitimate credentials, many traditional defenses become far less effective.

For MSPs, this creates a growing challenge as they must secure not only devices and networks, but also the identities that connect them. For IT teams, it reinforces the need to treat identity security as a core security control rather than an add-on.

How WatchGuard Secures Modern Identities

WatchGuard helps organizations defend against identity-based attacks through AuthPoint Total Identity Security, which combines phishing-resistant MFA, passkeys, dark web credential monitoring, and zero-trust access controls into a single solution. By protecting identities before attackers can exploit them, MSPs and IT teams can significantly reduce the risk of account compromise and unauthorized access.

Learn more: https://www.watchguard.com/wgrd-products/authpoint

Threat Trend: Attackers Are Hiding in Normal Endpoint Activity

The report also shows a sharp decline in PowerShell detections, historically a favorite tool for attackers. This doesn't mean attacks are decreasing. Rather, it suggests adversaries are evolving their techniques and becoming more effective at blending into legitimate activity.

Today's threats are increasingly fileless, behavioral, and designed to bypass traditional antivirus technologies.

Organizations need visibility into what is happening on endpoints long before ransomware is deployed or data is exfiltrated.

How WatchGuard Detects Threats Earlier

WatchGuard Endpoint Security and EPDR provide prevention, detection, investigation, and response capabilities within a unified platform. By continuously monitoring endpoint behavior and identifying suspicious activities such as lateral movement, persistence mechanisms, privilege escalation, and unauthorized remote access, organizations can stop threats earlier in the attack chain. MSPs benefit from centralized management and reduced alert fatigue, while IT teams gain actionable visibility across their environments.

Learn more: https://www.watchguard.com/wgrd-products/endpoint-security

Threat Trend: A Quieter Network Doesn't Mean a Safer Network

While average network attack volumes declined, the report found a significant increase in unique IPS signatures and a broader distribution of attack activity. Generic web-shell attacks became some of the most widespread network threats observed globally.

In other words, attackers are casting wider nets while making individual attacks less conspicuous.

For IT teams and MSPs, this means traditional alert-based monitoring may miss important indicators of compromise hidden among low-volume activity.

How WatchGuard Delivers Unified Visibility Across Network and Cloud Environments

WatchGuard's Unified Security Platform correlates signals from identity, endpoint, network, and cloud environments into a single operational view. Rather than forcing security teams to manage multiple disconnected tools, the platform provides centralized visibility and automated threat correlation, making it easier to identify emerging attacks that span multiple attack surfaces.

This visibility becomes increasingly important as attackers shift their activity to cloud applications and SaaS platforms, where traditional network monitoring may have limited visibility. WatchGuard CloudDR helps organizations detect suspicious activity within Microsoft 365 environments, uncovering compromised accounts, risky user behaviors, and cloud-based attack techniques that may otherwise remain hidden.

By combining endpoint, network, identity, and cloud telemetry, security teams gain a more complete picture of modern attack chains and can respond faster to emerging threats.

Learn more:

Unified Security Platform: https://www.watchguard.com/wgrd-solutions/unified-security-platform

CloudDR: https://www.watchguard.com/wgrd-products/sase/cloud-detection-response

Threat Trend: Attackers Continue to Exploit Decade-Old Vulnerabilities

One of the most surprising findings from the report is how frequently attackers continue to exploit vulnerabilities that have been publicly known for years. The median vulnerability referenced by the top attack signatures dates back to 2014, while SQL injection remains one of the most common attack methods.

This highlights a reality every MSP and IT administrator understands: patching every vulnerability immediately is rarely possible.

Security teams need protection that assumes some vulnerabilities will remain exposed.

How WatchGuard Reduces Exposure to Known Vulnerabilities

WatchGuard Firebox appliances provide layered network defenses that help reduce risk even when vulnerabilities remain unpatched. Intrusion Prevention Services (IPS), application control, web filtering, DNS protection, and advanced threat detection work together to block exploit attempts before they can compromise systems. This gives organizations valuable protection while patching and remediation efforts are underway.

Learn more: https://www.watchguard.com/wgrd-products/firewalls

Threat Trend: Encrypted Traffic Has Become Attackers' Preferred Delivery Channel

Perhaps the most alarming statistic in the report is that 95% of malware is now delivered through TLS-encrypted communications.

Attackers know that many organizations do not inspect encrypted traffic, creating a significant blind spot where malicious payloads, command-and-control communications, and malware downloads can operate undetected.

As encrypted traffic becomes the default, visibility becomes a critical security requirement.

How WatchGuard Reveals Hidden Threats in TLS Traffic

WatchGuard Firebox solutions provide HTTPS and TLS inspection capabilities, allowing organizations to decrypt, inspect, and re-encrypt traffic safely to identify threats hidden inside encrypted sessions. Combined with advanced malware protection and threat intelligence, MSPs and IT teams gain visibility into the traffic that attackers increasingly rely on to evade detection.

Learn more: https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/proxies/https/https_proxy_contentinspection_c.html

Threat Trend: Security Teams Are Overwhelmed by Complexity

Taken together, these findings point to a broader problem. Modern attacks span identities, endpoints, networks, cloud applications, and encrypted channels simultaneously.

Yet many organizations continue to rely on disconnected security tools that create operational complexity, visibility gaps, and slower response times.

The challenge facing both MSPs and internal IT teams is no longer finding more security products. It's finding a security architecture that can work together.

How WatchGuard Extends Security Operations 24/7

With WatchGuard MDR, organizations gain 24/7 monitoring, threat hunting, investigation, validation, and response across endpoint, identity, network, and cloud environments. Built on the WatchGuard Unified Security Platform, MDR combines AI-driven analytics with expert human analysts to identify and contain threats quickly, without requiring organizations to build and staff their own SOC.

Learn more: https://www.watchguard.com/wgrd-products/managed-services/mdr

The Real Takeaway for MSPs and IT Leaders

The latest Global Threat Report is not simply a record of what attackers did during the first half of the year. It's a blueprint for where cybersecurity is headed.

Attackers are exploiting identities instead of malware, encrypted communications instead of open channels, persistence instead of brute force, and old vulnerabilities instead of expensive zero-days.

Organizations need a security approach that can keep pace.

By unifying identity protection, endpoint security, network defense, threat detection, and managed response, WatchGuard helps MSPs deliver stronger security services and enables IT teams to protect their organizations against the threats that matter most today.

Read the full WatchGuard Global Threat Report here.