
Source composition
Two of the reporting sources listed are public fail2ban aggregators: Blocklist.net.ua and Blocklist.de. These services report IPs currently attempting SSH and login brute-forcing against a broad, independently monitored host pool. That’s the input class threat intelligence in this system is built from: observed, repeated hostile behavior reported by third parties, correlated alongside Alliance member submissions.Volume and update frequency
The panel reports 47,797 new IPs first seen, up 19% over the comparison period, and 454,298 submissions, up 304%. A spike of that size typically indicates either infrastructure cycling through fresh IP ranges or a scanning campaign sweeping in a large batch of previously unflagged hosts. A blocklist updated once a day would lag behind a change of this magnitude before it could be pulled and applied. The submission rate reflects how quickly new indicators become available for enforcement.Sources and infrastructure
Top reporting countries for this window were the Netherlands, the US, Romania, and Singapore, with UNMANAGED LTD (AS47890) identified as the top offending ASN. The bar chart shows how much of this traffic was matched and blocked across the enforcement types already in place — Checkpoint and Fortinet feeds — with the same intelligence enforced consistently across both.Proof of Value engagements analyze a client’s own edge traffic against this feed. Start a Proof of Value.

