Threat Intelligence Briefing
Analysis period: 2025-12-13T06:00:02.225582 - 2025-12-13T12:00:02.225582 (6 hours)
Executive Summary
The global threat landscape showed a slight decrease of 1.6% over the past 6 hours, with 873,019 threats detected from 436,243 unique IPs. The US (164,368) and China (145,220) remained the top sources, while the Netherlands (39,501) and Brazil (37,621) followed. Nordic countries saw notable activity, with Sweden (6,035 threats) leading, followed by Finland (2,316) and Norway (1,193). High-threat and SSH brute-force attacks dominated in the region. Globally, suspicious activity (635,314) and severe abuse (167,227) were the most common categories, with Russia's <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (15 attacks) and the Netherlands' <a href="https://ip.wayscloud.services/ip-intelligence/134.122.53.16" target="_blank">134.122.53.16</a> (12 attacks) being the busiest malicious IPs. SSH brute-force attacks persisted as the primary vector, particularly from datacenter IPs in the Netherlands and Bulgaria. Organizations should prioritize blocking these IPs and enhance SSH security with rate-limiting and multi-factor authentication.