Threat Intelligence Briefing
Analysis period: 2025-12-16T06:00:02.240318 - 2025-12-16T12:00:02.240318 (6 hours)
Executive Summary
The global threat landscape showed a slight 1.5% decrease in activity over the past 6 hours, with 863,583 total threats detected. The US (160,992) and China (144,430) remained top sources, while Nordics saw Sweden (5,840) and Finland (2,318) as most active, primarily facing SSH brute force, CMS attacks, and DDoS. Suspicious activity dominated 72% of global threats, with severe abuse at 19%. Nordic attacks focused on web services, particularly SSH brute force in Sweden and Denmark, where <a href="https://ip.wayscloud.services/ip-intelligence/45.148.10.240" target="_blank">45.148.10.240</a> (NL) targeted systems 11 times. Monitor these SSH-focused IPs: <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (RU, 12 attacks), <a href="https://ip.wayscloud.services/ip-intelligence/80.94.92.40" target="_blank">80.94.92.40</a> (RO, 9 attacks). Recommending immediate firewall rules for port 22 and CMS patching, especially for Nordic hosting providers seeing concentrated SSH attacks from Dutch and Russian IPs.