Threat Intelligence Briefing
Analysis period: 2025-12-19T18:00:01.624995 - 2025-12-20T00:00:01.624995 (6 hours)
Executive Summary
Global threat activity decreased slightly by 1.8% compared to the previous 6-hour period, with 858,615 incidents recorded. The US (160,417) and China (141,719) remained the top source countries, while Nordic countries showed varied activity: Sweden led with 5,432 threats, followed by Finland (2,415), Norway (1,183), Denmark (1,066), and Iceland (213). Suspicious activity dominated globally (72% of cases), with severe abuse (20%) and high threats (3.2%) as secondary concerns. Nordic threats focused on web attacks, brute force attempts, and Tor exit nodes in Sweden and Norway. Notable IPs include <a href="https://ip.wayscloud.services/ip-intelligence/5.187.35.21" target="_blank">5.187.35.21</a> (NL) and <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (RU), both conducting SSH brute force attacks at high frequency. Tactical analysis reveals concentrated SSH brute force attempts from European ISPs, particularly targeting cloud infrastructure. Immediate firewall rule updates for ports 22 and 80 are recommended, with enhanced monitoring for traffic from NL, RU, and RO IP ranges. Nordic organizations should prioritize web application firewall reviews given regional web attack patterns.