Threat Intelligence Briefing
Analysis period: 2026-01-15T06:00:01.788486 - 2026-01-15T12:00:01.788486 (6 hours)
Executive Summary
Global threat activity decreased sharply by 92% compared to the previous 6-hour period, with 1,365 events recorded. This is consistent with typical weekend patterns where automated scanning activity often drops. Sweden remains the most targeted Nordic country with 83 events, primarily attacks and SSH brute force attempts from 42 unique IPs. The top attacking IPs show concentrated SSH brute force activity, with <a href="https://ip.wayscloud.services/ip-intelligence/45.135.232.92" target="_blank">45.135.232.92</a> (<a href="https://ip.wayscloud.services/country-intelligence/RU" target="_blank">RU</a>) and <a href="https://ip.wayscloud.services/ip-intelligence/195.178.110.30" target="_blank">195.178.110.30</a> (<a href="https://ip.wayscloud.services/country-intelligence/BG" target="_blank">BG</a>) being the most persistent. Given the predictable drop in volume, defenders should maintain standard monitoring but prioritize investigating any SSH brute force attempts from the highlighted IP clusters, particularly those originating from Russian and Bulgarian networks. Temporary rate-limiting measures for these ASNs may reduce noise without impacting legitimate traffic.