Viewing historical forecast View Latest
AI Threat Forecast 2025-12-02T18:00:29.739310 #127

Threat Intelligence Briefing

Analysis period: 2025-12-02T12:00:01.774854 - 2025-12-02T18:00:01.774854 (6 hours)

Executive Summary

The threat landscape has shown a dramatic 278.4% increase in activity over the past 6 hours, with 1,245 threats detected globally. Nordic countries reported limited but notable activity: Sweden (7 attacks), Norway (5 attacks), and Finland (1 attack), primarily involving severe_abuse and ssh_bruteforce. The US (337 threats), China (131), and Singapore (106) were the top attack sources, with severe_abuse dominating at 1,000 incidents. SSH-related attacks (ssh_bruteforce, ssh-bruteforce) accounted for 245 cases, indicating a persistent focus on credential compromise. Key malicious IPs include <a href="https://ip.wayscloud.services/ip-intelligence/45.140.17.124" target="_blank">45.140.17.124</a> (RU, 11 attacks) and <a href="https://ip.wayscloud.services/ip-intelligence/195.178.110.30" target="_blank">195.178.110.30</a> (BG, 9 attacks), both conducting SSH bruteforce campaigns. Network defenders should prioritize blocking these IPs and enhance SSH security with rate-limiting and multi-factor authentication. Nordic organizations should scrutinize traffic from residential IPs in Sweden and Norway, where severe_abuse cases originated.