Viewing historical forecast View Latest
AI Threat Forecast 2025-10-21T18:00:04.196718 #35

Threat Intelligence Briefing

Analysis period: 2025-10-21T12:00:01.726961 - 2025-10-21T18:00:01.726961 (6 hours)

Executive Summary

The threat landscape has intensified, evidenced by a 15.1% surge in global malicious activity compared to the prior six-hour window. SSH brute-force attacks constitute the overwhelming majority of threats, accounting for 97% of reported events. Romania, Russia, and Iran are the top originating countries for these attacks. We observed no significant activity within Nordic countries this period. The attacks appear to be broadly distributed across residential and datacenter IPs, with no single ISP or hosting provider disproportionately affected. No notable Tor exit node activity was detected. Given the prevalence of SSH brute-forcing, focus monitoring on networks exhibiting high volumes of failed SSH authentication attempts, particularly originating from RO, RU and IR. Prioritize analysis of traffic to exposed SSH ports. Defenders should enforce strong password policies and consider implementing multi-factor authentication. Track emerging brute-force techniques targeting other services.