Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product Designs
ID: 5658bb16-439d-5c81-846a-3a23f098042f
STIX ID: report--5658bb16-439d-5c81-846a-3a23f098042f
Feed Name: cybersecurityNews.com
Cl0p-affiliated actors are actively exploiting a critical unauthenticated deserialization flaw (CVE-2026-12569) in PTC Windchill PDMLink and FlexPLM to achieve RCE, install JSP webshells, stage and exfiltrate engineering/product-design data, and perform double-extortion via mass internal extortion emails; the report includes IoCs (IP addresses, a SHA-256 hash, malicious header, webshell path, reconnaissance request and response size) and urges immediate patching, forensic hunting for unexpected JSP files and unusual outbound activity, and log review for the noted reconnaissance request.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
