Threat Intelligence Briefing
Analysis period: 2025-12-22T18:00:01.599617 - 2025-12-23T00:00:01.599617 (6 hours)
Executive Summary
The global threat landscape showed a slight decrease of 2.2% over the past 6 hours, with 840,762 threats detected from 420,594 unique IPs. Suspicious activity dominated (71.5% of threats), followed by severe abuse (20.1%). The US (158,504) and China (137,731) remained top sources, while the Netherlands (44,192) and Singapore (37,597) showed significant activity. Nordic countries accounted for 10,041 threats, led by Sweden (5,229) with high_threat and SSH brute-force attacks, Finland (2,363) with bruteforce patterns, and Norway (1,251) with severe abuse incidents. Key threats included Russian IP <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (11 bruteforce attacks) and Dutch IPs <a href="https://ip.wayscloud.services/ip-intelligence/178.62.197.119" target="_blank">178.62.197.119</a> and <a href="https://ip.wayscloud.services/ip-intelligence/134.122.56.247" target="_blank">134.122.56.247</a> (10 and 7 SSH brute-force attacks respectively). Monitor these IPs closely, especially for repeated SSH attacks. Nordic networks should prioritize SSH hardening and review logs for patterns from these high-activity IPs.