Viewing historical forecast View Latest
AI Threat Forecast 2025-12-06T18:01:04.602822 #141

Threat Intelligence Briefing

Analysis period: 2025-12-06T12:00:02.168495 - 2025-12-06T18:00:02.168495 (6 hours)

Executive Summary

The global threat landscape has surged by 149.1% compared to the previous 6-hour period, with 10,779 threats detected from 9,016 unique IPs across 93 countries. Malware command-and-control (C2) dominated at 6,951 incidents, followed by severe abuse (958) and attacks (832). Nordic activity remained relatively low, with Norway (24 threats, 14 IPs) seeing attacks, brute force, and severe abuse, while Sweden (8 threats) showed similar patterns alongside SSH brute force. Finland reported only 3 severe abuse cases. Key attack sources included the US (590), China (486), and the Netherlands (401). Tactical intelligence highlights persistent brute force and SSH attacks from IPs like <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (RU) and <a href="https://ip.wayscloud.services/ip-intelligence/159.65.203.140" target="_blank">159.65.203.140</a> (NL). These IPs targeted SSH services repeatedly, indicating coordinated campaigns. Organizations should prioritize SSH hardening, monitor Dutch and Russian IP ranges, and implement rate-limiting for SSH access. Nordic entities should remain vigilant for localized brute force attempts.