Viewing historical forecast View Latest
AI Threat Forecast 2025-12-12T06:00:58.183771 #157

Threat Intelligence Briefing

Analysis period: 2025-12-12T00:00:02.044650 - 2025-12-12T06:00:02.044650 (6 hours)

Executive Summary

Global threat activity increased by 3.4% in the past 6 hours, with 895,466 recorded threats. Suspicious activity dominated (70.7%), followed by severe abuse (18.8%). The US (169,628) and China (145,701) remained top sources. Nordic countries showed concerning patterns: Sweden led with 6,183 threats (primarily suspicious activity and brute force attacks), followed by Finland (2,398) and Norway (1,191). Denmark (1,112) and Iceland (222) saw moderate scanning and SSH brute force attempts. Notably, 45% of Nordic threats originated from datacenter IPs. Monitor high-risk IPs like <a href="https://ip.wayscloud.services/ip-intelligence/174.138.2.95" target="_blank">174.138.2.95</a> (NL) and <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (RU), both conducting 11 SSH brute force attacks each. The Dutch ISP LeaseWeb hosted three of the top five malicious IPs. Recommend blocking /24 subnets from AS14061 (DigitalOcean NL) and enhancing SSH rate limits, as 68% of Nordic attacks targeted port 22.