Threat Intelligence Briefing
Analysis period: 2026-01-20T18:00:01.349154 - 2026-01-21T00:00:01.349154 (6 hours)
Executive Summary
Global threat activity decreased by 37.7% vs the previous period, with 1,801 events observed. The US and Netherlands remain the top source countries, accounting for over 50% of attacks. SSH brute force attempts persist as the dominant attack vector, with IPs from Bulgaria (<a href="https://ip.wayscloud.services/ip-intelligence/195.178.110.30" target="_blank">195.178.110.30</a>) and Russia (<a href="https://ip.wayscloud.services/ip-intelligence/176.120.22.13" target="_blank">176.120.22.13</a>) being most active. Nordic countries show stable low-volume activity, consistent with their 7-day averages. Norway recorded 6 events from 2 IPs, primarily brute force and web attacks. The decline in overall activity suggests possible attacker shift to other targets or infrastructure changes. Consider temporary rate-limiting for SSH traffic from ASNs historically linked to brute force campaigns, particularly those in NL and US CIDR ranges. Deprioritize individual IP blocking unless they exhibit sustained high-volume patterns, as most threats are ephemeral. Nordic defenders should maintain existing controls given the stable baseline.