[Global Cybersecurity Report] Since 2025, with the rapid evolution of artificial intelligence (AI) technology towards agentization, the autonomy and concealment of cyber attacks have significantly increased, posing severe challenges to the global cybersecurity protection system. Against this backdrop, firewalls, as core infrastructure for cybersecurity, are accelerating their iteration towards cloud-native, SASE-integrated, and AI-driven directions, forming a new defense pattern of "combating intelligence with intelligence." Industry data shows that the cloud-native firewall market is expected to grow at a compound annual growth rate of 18%, and AI-driven Next-Generation Firewalls (NGFW) have become the core security choice for enterprises in their digital transformation.

The current cyber threat landscape exhibits distinct new characteristics. On one hand, AI agents have been widely applied in cyber attacks. Attackers can use AI to automatically complete vulnerability exploration, malicious code generation, and attack path planning, and even independently decide on target files for encryption, greatly shortening the attack preparation cycle and enhancing concealment. In the foreign cyber attack on the Harbin Asian Winter Games earlier this year, the attackers used AI agents to write dynamic code to launch the attack, and such technical means have become important tools for state-sponsored cyber attacks. On the other hand, the abuse of generative AI has spawned a large number of deepfake attacks, ranging from fake videos imitating celebrities for product promotion to face-swapping attacks that bypass identity verification in financial institutions. Such threats have penetrated multiple fields such as people‘s livelihood, finance, and education, posing multiple risks to personal rights and industry security.

In response to the escalating threats, the firewall technology system is undergoing structural changes. The in-depth implementation of cloud-native architecture has become the primary trend. The rigid architecture of traditional hardware firewalls can no longer meet the needs of enterprises‘ multi-cloud strategies, and cloud-native firewalls with elastic scalability and cross-cloud management capabilities have gradually become mainstream. Gartner predicts that 30% of new branch office firewall deployments in 2025 will adopt the Firewall-as-a-Service (FWaaS) model. Cloud firewalls launched by vendors such as Alibaba Cloud and Huawei Cloud have achieved elastic scalability of 10 million-level QPS, effectively addressing sudden traffic scenarios such as e-commerce promotions.

The collaborative integration of SASE and zero-trust architecture has reconstructed the enterprise security perimeter. Embedding firewall capabilities into SD-WAN nodes to achieve integrated "networking + security" services has become the core protection solution for hybrid office scenarios. After deploying the relevant solution, a multinational enterprise increased the interception rate of phishing attacks on remote access from 65% to 98% and improved security operation and maintenance efficiency by 40%. At the same time, AI technology is comprehensively reshaping the threat defense capabilities of firewalls. Many vendors have launched AI agent-based threat detection systems, reducing the average detection time from hours to minutes through dynamic sparse activation mechanisms, and increasing the detection rate of unknown threats to over 95%. According to a practical case of Sangfor in February this year, its AI-driven firewall identified and intercepted a new type of hacking tool within 5 minutes, and subsequently successfully resisted more than 60,000 attack attempts from the same source.

Industry experts point out that the current cybersecurity offensive and defensive landscape has entered an "agent-driven" new stage, and the core value of firewalls has shifted from traditional traffic filtering to systematic collaborative defense. Neil Jardon, Director of the Interpol Cybercrime Directorate, emphasized that the global economic scale of cybercrime has exceeded 10.5 trillion US dollars, and addressing such threats requires global collaboration, with technological innovation and international cooperation being the key. In the future, with the advancement of quantum security technology research and edge AI reasoning, firewalls will further evolve towards an intelligent defense system with proactive prediction and real-time response, laying a solid security foundation for the development of the digital economy.