Threat Intelligence Briefing
Analysis period: 2025-12-18T00:00:01.479095 - 2025-12-18T06:00:01.479095 (6 hours)
Executive Summary
The global threat landscape showed a 2.2% increase in activity over the past 6 hours, with 872,122 threats detected from 433,705 unique IPs. The US (162,446) and China (144,539) led in attack volume, while the Nordic region saw Sweden (5,680) and Finland (2,459) as primary targets. Suspicious activity (71.6%) and severe abuse (19.4%) dominated globally, with Nordic countries facing high-threat SSH brute force and web attacks. Iceland stood out with Tor exit node activity among its 219 threats. Key IPs to monitor include <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (Russia) and <a href="https://ip.wayscloud.services/ip-intelligence/167.172.36.25" target="_blank">167.172.36.25</a> (Netherlands), both conducting SSH brute force attacks. Attack patterns show a shift toward credential stuffing via residential IPs. Recommendations: prioritize blocking /24 networks hosting repeat offenders and implement SSH key-based authentication for Nordic-facing services.