Threat Intelligence Briefing
Analysis period: 2025-12-01T12:00:02.555061 - 2025-12-01T18:00:02.555061 (6 hours)
Executive Summary
The global threat landscape has intensified, showing a 23.7% increase in attacks over the past 6 hours, totaling 370 incidents. SSH brute-force attacks dominated (83.2% of cases), with Singapore (67 attacks), the US (40), and Romania (28) as top sources. Nordic regions saw limited activity, with Sweden (2 attacks) and Finland (1) reporting SSH brute-force attempts. Notably, Russia's <a href="https://ip.wayscloud.services/ip-intelligence/45.140.17.124" target="_blank">45.140.17.124</a> (14 attacks) and Bulgaria's <a href="https://ip.wayscloud.services/ip-intelligence/195.178.110.30" target="_blank">195.178.110.30</a> (9 attacks) were most aggressive, targeting multiple SSH variants. No Tor exit nodes were detected. Defenders should prioritize blocking these IPs and reinforce SSH authentication, as 96.5% of threats focused on credential compromise. Nordic networks remain secondary targets but require continued monitoring given the persistent SSH focus.