Viewing historical forecast View Latest
AI Threat Forecast 2025-12-21T12:01:13.985490 #189

Threat Intelligence Briefing

Analysis period: 2025-12-21T06:00:01.950789 - 2025-12-21T12:00:01.950789 (6 hours)

Executive Summary

The global threat landscape showed a slight decrease of 1.3% compared to the previous 6-hour period, with 861,760 threats detected from 430,689 unique IPs across 210 countries. The US (161,316) and China (142,767) remained the top sources, while suspicious activity (626,658) dominated threat categories. In the Nordic region, Sweden (5,447 threats) led with attacks and brute force attempts, followed by Finland (2,392) and Norway (1,278). Denmark (1,075) exhibited web-based attacks, while Iceland (226) showed moderate threat activity. Notably, SSH brute force attacks were prevalent across Nordic countries, with Finland and Denmark showing increased spam activity. Key IPs to monitor include <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (RU) and <a href="https://ip.wayscloud.services/ip-intelligence/167.71.75.23" target="_blank">167.71.75.23</a> (NL), both involved in severe abuse and SSH brute force attacks. The Netherlands-based IPs <a href="https://ip.wayscloud.services/ip-intelligence/134.209.204.195" target="_blank">134.209.204.195</a> and <a href="https://ip.wayscloud.services/ip-intelligence/157.245.74.247" target="_blank">157.245.74.247</a> also showed persistent SSH brute force patterns. Recommendations include tightening SSH access controls, blocking high-risk IPs, and enhancing monitoring for web-based brute force attempts, particularly in Nordic networks.