Viewing historical forecast View Latest
AI Threat Forecast 2025-12-22T12:02:13.678192 #192

Threat Intelligence Briefing

Analysis period: 2025-12-22T06:00:02.091783 - 2025-12-22T12:00:02.091783 (6 hours)

Executive Summary

The global threat landscape showed a slight decrease of 1.7% compared to the previous 6-hour period, with 855,145 total threats detected. Nordic countries accounted for 10,272 threats, with Sweden (5,390) and Finland (2,390) as the most active. The US (160,599) and China (141,290) remained the top source countries globally. Nordic threats were dominated by SSH brute force attacks, web attacks, and suspicious activity. Sweden notably saw a concentration of brute force attempts, while Norway (1,266) and Denmark (1,004) primarily faced high-threat and severe abuse patterns. Iceland (222) showed minimal activity but followed similar threat categories. The data highlights persistent SSH targeting across Nordic infrastructure, particularly in Sweden and Finland. High-priority IPs to monitor include <a href="https://ip.wayscloud.services/ip-intelligence/195.178.110.30" target="_blank">195.178.110.30</a> (Bulgaria) and <a href="https://ip.wayscloud.services/ip-intelligence/167.71.1.85" target="_blank">167.71.1.85</a> (Netherlands), both linked to 11 SSH brute force attacks each. The Netherlands and Russia were recurrent sources of SSH-focused threats, with <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (Russia) and <a href="https://ip.wayscloud.services/ip-intelligence/178.62.224.31" target="_blank">178.62.224.31</a> (Netherlands) showing consistent patterns. Recommendations include hardening SSH configurations, implementing rate limiting, and scrutinizing traffic from NL and RU datacenters. Nordic ISPs should prioritize alerts for repeated authentication attempts from these IP ranges.