Threat Intelligence Briefing
Analysis period: 2026-01-02T12:00:02.138095 - 2026-01-02T18:00:02.138095 (6 hours)
Executive Summary
Global threat activity increased by 17.4% vs the previous period, driven primarily by attacks (742 events) and malware C2 (379 events). Russian IPs <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> and <a href="https://ip.wayscloud.services/ip-intelligence/45.140.17.124" target="_blank">45.140.17.124</a> were the most active, each conducting 14 SSH brute force attacks. Nordic activity remains low, with Denmark showing the highest volume (6 events), consistent with regional baselines. The Netherlands (459 events) and Canada (508 events) dominated global traffic, suggesting continued abuse of hosting infrastructure in these jurisdictions. Consider temporary rate-limiting for SSH traffic from Russian and Bulgarian ASNs, which accounted for 28 brute force events. Nordic defenders should maintain existing web application controls, as local threat levels show no significant deviation.