Viewing historical forecast View Latest
AI Threat Forecast 2025-10-22T12:00:03.838119 #38

Threat Intelligence Briefing

Analysis period: 2025-10-22T06:00:01.291523 - 2025-10-22T12:00:01.291523 (6 hours)

Executive Summary

Threat activity has decreased by 7.3% in the last 6 hours, dominated by SSH brute-force attacks which account for 98% of all reported threats. Compromised datacenters are the primary source of attacks. A single SSH brute-force attack source was observed originating from Sweden. Threat actors are primarily leveraging infrastructure in Russia, Iran, China, and Romania. No significant Tor exit node activity was observed. Given the prevalence of SSH brute-force attempts, prioritize monitoring network traffic to ports 22 and 2222. Pay close attention to traffic originating from ASNs associated with DigitalOcean and Hetzner, as these are frequently abused for this type of activity. Track IPs 45.140.17.124, 194.0.234.19, 45.134.26.79, 45.135.232.177, and 62.60.131.157, as they are exhibiting high attack volume.