Threat Intelligence Briefing
Analysis period: 2025-12-21T18:00:01.947717 - 2025-12-22T00:00:01.947717 (6 hours)
Executive Summary
The global threat landscape showed a slight 2.5% decrease in activity over the past 6 hours, with 846,687 threats detected from 423,316 unique IPs. Suspicious activity dominated (72%), followed by severe abuse (20%). The US and China led in attack sources, while Nordic countries saw notable activity: Sweden (5,345 threats) faced attacks and brute force attempts, Finland (2,371) experienced VoIP and web attacks, and Norway (1,261) dealt with spam and brute force. Denmark (1,001) and Iceland (222) reported high-threat activities. The top attacking IPs were <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (Russia) and <a href="https://ip.wayscloud.services/ip-intelligence/178.62.232.238" target="_blank">178.62.232.238</a> (Netherlands), both conducting SSH brute force attacks. Monitor these IPs closely, especially for repeated SSH brute force attempts. Prioritize patching SSH services and implement rate-limiting for Nordic networks facing concentrated attack patterns.