logo

Cl0p Targets 40+ Organizations Through PTC Windchill Flaw

ID: f1bc4efd-b284-51d3-8099-b36b6175dc73

STIX ID: report--f1bc4efd-b284-51d3-8099-b36b6175dc73

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

Author: Pierluigi Paganini

...
...

Cl0p has exploited a critical deserialization RCE in PTC Windchill and FlexPLM (CVE-2026-12569, CVSS 9.3) to deploy a sophisticated web-shell implant that decrypts credentials, maps and exfiltrates sensitive PLM data, and has allegedly impacted over 40 organizations; the campaign follows Cl0p's established mass-exploitation-then-extortion pattern and has been added to CISA's KEV catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.