Viewing historical forecast View Latest
AI Threat Forecast 2025-12-15T00:00:53.232405 #167

Threat Intelligence Briefing

Analysis period: 2025-12-14T18:00:01.921443 - 2025-12-15T00:00:01.921443 (6 hours)

Executive Summary

The global threat landscape showed a 2.2% decrease in activity over the past 6 hours, with 853,748 threats detected from 427,038 unique IPs across 209 countries. Suspicious activity dominated (71.9%), followed by severe abuse (19.7%). The US and China remained top sources, while Nordic countries accounted for 10,528 threats, led by Sweden (5,816), Finland (2,234), and Norway (1,184). Nordic threats primarily involved high-threat attacks, SSH brute force, and web attacks, with Sweden showing elevated SSH brute force activity. Notable IPs included <a href="https://ip.wayscloud.services/ip-intelligence/174.138.13.15" target="_blank">174.138.13.15</a> (NL) and <a href="https://ip.wayscloud.services/ip-intelligence/195.178.110.30" target="_blank">195.178.110.30</a> (BG), both targeting SSH services. Tactical intelligence highlights a shift toward SSH and web brute force attacks, particularly from Dutch and Bulgarian networks. Organizations should prioritize patching SSH vulnerabilities and monitor traffic from <a href="https://ip.wayscloud.services/ip-intelligence/45.148.10.240" target="_blank">45.148.10.240</a> (NL) and <a href="https://ip.wayscloud.services/ip-intelligence/178.128.92.222" target="_blank">178.128.92.222</a> (SG), which exhibited severe abuse patterns. Web application firewalls should be tuned to detect brute force attempts.