Threat Intelligence Briefing
Analysis period: 2026-01-11T12:00:01.666752 - 2026-01-11T18:00:01.666752 (6 hours)
Executive Summary
Global threat activity increased by 67.1% vs the previous period, with malware C2 (561 events) and attacks (451) dominating. The Netherlands (494 events) remains the top source, while Nordic activity remains low (7 events in Sweden, 4 in Norway). Russian IPs <a href="https://ip.wayscloud.services/ip-intelligence/45.140.17.124" target="_blank">45.140.17.124</a> and <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> are leading SSH brute force sources, consistent with a week-long campaign. This surge is abnormal, exceeding the 7-day average by over 50%. Consider temporary blocking of /24 ranges for ASNs hosting these Russian IPs, given their sustained pattern. Nordic defenders should prioritize SSH hardening over web attacks, which remain at baseline levels.