Threat Intelligence Briefing
Analysis period: 2025-12-14T06:00:01.355521 - 2025-12-14T12:00:01.355521 (6 hours)
Executive Summary
The global threat landscape saw a slight decrease of 1.4% in activity over the past 6 hours, with 868,605 threats detected from 434,081 unique IPs across 209 countries. Suspicious activity dominated (72.7%), followed by severe abuse (19.2%). The US (161,990) and China (144,895) remained top sources, while Nordic countries showed varied activity: Sweden (5,921 threats) led with high-threat and SSH brute-force attacks, followed by Finland (2,287) and Norway (1,194), where spam and brute-force attempts were notable. Denmark (1,102) and Iceland (206) showed lower volumes but similar threat patterns. Key IPs to monitor include <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (RU, 12 attacks) and <a href="https://ip.wayscloud.services/ip-intelligence/134.209.95.39" target="_blank">134.209.95.39</a> (NL, 9 attacks), both linked to SSH brute-forcing. SSH-related attacks remain prevalent, with <a href="https://ip.wayscloud.services/ip-intelligence/80.94.92.40" target="_blank">80.94.92.40</a> (RO) and <a href="https://ip.wayscloud.services/ip-intelligence/195.178.110.30" target="_blank">195.178.110.30</a> (BG) also active. Recommendations: Prioritize blocking SSH brute-force attempts, particularly from these IPs, and review Nordic-facing firewall rules for anomalies.