Threat Intelligence Briefing
Analysis period: 2025-12-19T06:00:01.491590 - 2025-12-19T12:00:01.491590 (6 hours)
Executive Summary
The global threat landscape showed a slight decrease of 1.5% compared to the previous 6-hour period, with 867,444 threats detected from 434,213 unique IPs across 211 countries. Suspicious activity dominated (632,012 incidents), followed by severe abuse (170,113). The US (162,896) and China (144,150) were top sources. In the Nordics, Sweden (5,559 threats) led regional activity, primarily from attacks and high-threat categories. Finland (2,456) showed web-based attacks, while Norway (1,193) and Denmark (1,089) had consistent high-threat patterns. Iceland (218) remained low-risk. Notably, IP <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (RU) conducted 11 SSH brute-force attacks. Monitor <a href="https://ip.wayscloud.services/ip-intelligence/195.178.110.30" target="_blank">195.178.110.30</a> (BG) and <a href="https://ip.wayscloud.services/ip-intelligence/146.190.20.203" target="_blank">146.190.20.203</a> (NL) for similar patterns. Recommendations: prioritize blocking Russian/Bulgarian IPs in Nordic-facing services and enhance SSH authentication controls.