Threat Intelligence Briefing
Analysis period: 2025-12-15T00:00:01.263573 - 2025-12-15T06:00:01.263573 (6 hours)
Executive Summary
Global threat activity increased 2.1% over the past 6 hours, with 872,117 incidents from 432,950 unique IPs. The Nordic region saw Sweden as the most targeted (5,948 attacks), followed by Finland (2,265), Norway (1,198), Denmark (1,092), and Iceland (220). Primary threat categories included suspicious activity (71.5% globally) and severe abuse (19.3%), with Nordic countries showing high rates of brute force attacks, web attacks, and SSH brute force. The US (163,015) and China (144,601) remained top attack sources globally, while the Netherlands (42,248) hosted notable malicious infrastructure. High-risk IPs include <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (RU) and <a href="https://ip.wayscloud.services/ip-intelligence/146.190.17.190" target="_blank">146.190.17.190</a> (NL), both conducting SSH brute force attacks. Attack patterns show a 12% increase in SSH-related threats targeting Nordic cloud providers. Immediate recommendations: block listed IPs, enforce SSH key authentication, and monitor traffic from NL/RU networks for brute force attempts.