ZeroFox Cyber Intelligence Daily Brief - December 14, 2024
|by Alpha Team

ZeroFox Cyber Intelligence Daily Brief - December 14, 2024
ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Here is today’s daily roundup to give you and your clients an advantage over the adversary.
Brief Highlights
- Vulnerable Prometheus Servers Pose Significant Security Risk
- Sophisticated Social Engineering Operation Mimic Law Enforcement to Target UAE Citizens
- Staying Safe This Holiday Season from Malicious Cyber Activities
Vulnerable Prometheus Servers Pose Significant Security Risk
What happened: Thousands of Prometheus servers are exposed online, making them vulnerable to attacks. Organizations are urged to secure their Prometheus servers and exporters to manage these risks and limit exposure.
Why it matters: These exposed servers could leak sensitive information, including credentials and application programming interface (API) key. They can likely be targeted with denial-of-service attacks or remote code execution attacks. Additionally, the widespread exposure of Prometheus servers can provide valuable intelligence to nation-state actors and other threat actors, enabling them to map out organizational networks and identify potential targets for future attacks.
Sophisticated Social Engineering Operation Mimic Law Enforcement to Target UAE Citizens
What happened: Researchers observed fraudsters impersonating Dubai Police in a phishing campaign targeting UAE mobile users. The scammers sent text messages with malicious URLs, prompting recipients to visit fake sites that harvested personal and financial data.
Why it matters: The disguised communications with malicious URLs used official branding to establish credibility and exploit public trust in law enforcement agencies for financial gain. The campaign used international infrastructure, including Tencent servers in Singapore, making it easier to evade tracing efforts. Victims of the campaign are likely at a risk of facing further targeted attacks, including spear phishing, doxxing, blackmail, and financial extortion.
Staying Safe This Holiday Season from Malicious Cyber Activities
What happened: The U.S. Department of the Treasury’s Office of Cybersecurity and Critical Infrastructure Protection (OCCIP) released an advisory highlighting tips for consumers to avoid cyber and online scams during the holiday season. Consumers are urged to stay vigilant against the increasing threat of online cyber scams and fraud by implementing appropriate cybersecurity measures.
Why it matters: Cybercriminals are targeting consumers through popular social media platforms, as well as, via wrong number texts in phishing campaigns. Scammers use high-impact words like “income,” “investment,” “credit,” and more to lure unsuspecting victims into sharing personal information by clicking on malicious links. Common scams shoppers need to watch out for are fake job offers, social media ads, and charity scams.
DEEP AND DARK WEB INTELLIGENCE
New Alliance of Hacktivists on Telegram: On December 12, 2024, pro-Palestine threat actor group "Anonymous Guys" announced an alliance with "Wolf Cyber Army," a pro-Palestine threat actor group that is also involved in the motivation of pro-Russia hacktivist groups.
VULNERABILITY AND EXPLOIT INTELLIGENCE
CVE-2024-54093: Some versions of Siemens Solid Edge SE2024 application are vulnerable to heap-based buffer overflow while parsing specially crafted ASM files. This could allow an attacker to execute code in the context of the current process.
Affected products: All versions of Solid Edge SE2024 prior to V224.0
Tags: DIB, tlp:green