Threat Intelligence Briefing
Analysis period: 2026-01-03T00:00:02.091715 - 2026-01-03T06:00:02.091715 (6 hours)
Executive Summary
Global threat activity changed by several orders of magnitude (2,356 → 20,605 events), representing a significant deviation from typical baseline. Attacks (4,952) and malware C2 (3,821) dominate, with Canada (3,350) and the US (2,918) as top origin countries. Nordic activity remains stable, with Sweden (55 events) showing consistent patterns of attacks and brute force. Russian IPs <a href="https://ip.wayscloud.services/ip-intelligence/45.140.17.124" target="_blank">45.140.17.124</a> and <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> are repeat SSH brute force offenders. Consider temporary blocking or rate-limiting Russian ASNs associated with SSH brute force clusters, as individual IPs are ephemeral. Deprioritize Nordic spam traffic, which aligns with historical baselines.