Threat Intelligence Briefing
Analysis period: 2025-12-18T18:00:01.620556 - 2025-12-19T00:00:01.620556 (6 hours)
Executive Summary
The global threat landscape showed a slight decrease of 1.6% in activity over the past 6 hours, with 857,115 threats detected. The US and China remained the top source countries, while Nordic countries saw concentrated activity. Sweden reported 5,505 threats, primarily attacks, brute force attempts, and suspicious activity. Finland followed with 2,427 threats, including web attacks and SSH brute force. Norway, Denmark, and Iceland showed lower but consistent threat volumes focused on high and moderate severity incidents. Suspicious activity accounted for 72% of global threats, with severe abuse comprising 20%.
Key threat actors include <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (Russia) and <a href="https://ip.wayscloud.services/ip-intelligence/159.223.230.85" target="_blank">159.223.230.85</a> (Netherlands), both conducting SSH brute force attacks. Attack patterns show a persistent focus on credential compromise, with 82% of Nordic incidents involving brute force methods. Immediate recommendations include blocking Russian and Dutch IP ranges <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.0" target="_blank">45.135.232.0</a>/24 and <a href="https://ip.wayscloud.services/ip-intelligence/159.223.224.0" target="_blank">159.223.224.0</a>/19, and implementing rate limiting for SSH authentication attempts across Nordic networks.