As part of our ongoing mission to enhance threat visibility and provide intelligent, proactive protection, WatchGuard is rolling out important updates to the Botnet Detection service on WatchGuard Firewalls.
These enhancements are designed to improve detection accuracy and expand the scope of threat intelligence, helping you identify more potentially malicious activity on your network. As a result, you may notice an increase in detection events, which is expected and reflects stronger visibility into emerging threats.
What’s Changing
Expanded Filtering of Threat Intelligence Feeds
We’ve updated how we filter threat data from our Proofpoint integration, following new guidance from their team. This change triples the number of suspicious IP addresses we monitor in the Botnet Detection service.
What to expect: You may see more botnet-related detections. This does not mean your network is under greater attack, it simply means your WatchGuard device now has a broader view of potentially risky activity.
New Brute Force Threat Category
We’re introducing a new category that flags IPs associated with brute-force login attempts, where attackers try to guess passwords to gain unauthorized access.
Why it matters: This update helps you detect and stop credential-guessing activity earlier. We also strongly recommend enabling Multifactor Authentication (MFA) wherever possible to protect against these attacks.
New Scanning Threat Category
The Scanning category flags IPs known for performing reconnaissance scans, a common precursor to targeted attacks.
How to manage it: While we recommend blocking these types of scans. WatchGuard maintains an allowlist of these trusted sources, and you can also manage custom exceptions through your device or WatchGuard Cloud.
What It Means for You
Don’t be alarmed by an increase in detections. These changes are expected and reflect improved visibility, not necessarily an increase in malicious activity. It’s important to review your Botnet Detection configuration and settings to ensure they match your organization’s needs and risk profile.
TIP: WatchGuard Cloud users can activate ThreatSync to add context to Botnet detections.
If you have questions about these changes or need support reviewing your detection policies, our support team and WatchGuard Partners are here to help.
At WatchGuard, security is our top priority. We're committed to providing our customers with the latest protection against evolving cyber threats. Today, we're pleased to announce the availability of Fireware v12.11.2, which addresses several bugs and some minor functional updates.
Which products are affected by this release?
Upgrade Now and Stay Protected
We strongly recommend that all Firebox users upgrade to this update immediately. Upgrading to Fireware v12.11.2 is simple. Complete upgrade instructions and the firmware can be downloaded from the WatchGuard Software Downloads page. If you have Fireboxes connected to WatchGuard Cloud, you can upgrade the firmware immediately or schedule the upgrade for a future time.
Notable enhancements in this release include:
For additional information on this update, please refer to the Fireware v12.11.2 Release Notes.
Stay Informed
WatchGuard is committed to keeping our customers informed about the latest security threats. For the most up-to-date information on vulnerabilities and how WatchGuard products address them, please visit our Trust Center. Please contact your local WatchGuard representative if you have any additional questions about this release. For Sales or Support questions, you can find phone numbers for your region online. If you contact WatchGuard Technical Support, please have your registered appliance Serial Number or Partner ID available.