Viewing historical forecast View Latest
AI Threat Forecast 2025-12-02T00:00:25.796441 #124

Threat Intelligence Briefing

Analysis period: 2025-12-01T18:00:01.715598 - 2025-12-02T00:00:01.715598 (6 hours)

Executive Summary

The threat landscape shows a 2.7% increase in global attacks over the past 6 hours, totaling 380 incidents from 290 unique IPs across 46 countries. SSH brute-force attacks dominate (305 incidents), followed by general brute-force (49) and SSH-bruteforce (23). Romania (RO), Singapore (SG), and the US (US) are top sources. Nordic activity remains low, with Sweden (SE) recording 2 attacks (bruteforce and SSH brute-force). Notable IPs include <a href="https://ip.wayscloud.services/ip-intelligence/45.140.17.124" target="_blank">45.140.17.124</a> (RU, 12 attacks) and <a href="https://ip.wayscloud.services/ip-intelligence/195.178.110.30" target="_blank">195.178.110.30</a> (BG, 7 attacks), both targeting SSH services. Tactically, monitor Romanian IPs <a href="https://ip.wayscloud.services/ip-intelligence/2.57.121.112" target="_blank">2.57.121.112</a> and <a href="https://ip.wayscloud.services/ip-intelligence/2.57.121.25" target="_blank">2.57.121.25</a> (6 and 5 SSH brute-force attacks respectively). The Netherlands' <a href="https://ip.wayscloud.services/ip-intelligence/206.189.100.33" target="_blank">206.189.100.33</a> also shows repeated SSH targeting. No Tor exit nodes or datacenter patterns were detected. Prioritize SSH hardening and block high-volume IPs, especially from Eastern Europe.