Threat Intelligence Briefing
Analysis period: 2025-12-17T06:00:01.891758 - 2025-12-17T12:00:01.891758 (6 hours)
Executive Summary
The global threat landscape showed a slight decrease of 1.5% in the last 6 hours, with 862,233 threats detected from 431,222 unique IPs. Suspicious activity dominated (72.9%), followed by severe abuse (19.4%). The US (160,479) and China (144,626) remained top sources. Nordic countries saw significant activity: Sweden led with 5,725 threats (primarily attacks and botnets), Finland had 2,308 (ssh_brute_force prominent), Norway reported 1,173 (web attacks and spam), while Denmark (1,119) and Iceland (222) showed high-threat patterns. SSH bruteforce and web attacks were prevalent across the region. Key IPs to monitor include <a href="https://ip.wayscloud.services/ip-intelligence/164.90.192.59" target="_blank">164.90.192.59</a> (Netherlands, 10 attacks) and <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (Russia, 10 bruteforce attempts). Nordic ISPs should prioritize SSH hardening and web application firewalls given the regional focus on credential attacks. Organizations should review logs for traffic from these IPs immediately.