Cl0p Targets 40+ Organizations Through PTC Windchill Flaw
ID: f1bc4efd-b284-51d3-8099-b36b6175dc73
STIX ID: report--f1bc4efd-b284-51d3-8099-b36b6175dc73
Feed Name: Security Affairs
Threat Score
Cl0p has exploited a critical deserialization RCE in PTC Windchill and FlexPLM (CVE-2026-12569, CVSS 9.3) to deploy a sophisticated web-shell implant that decrypts credentials, maps and exfiltrates sensitive PLM data, and has allegedly impacted over 40 organizations; the campaign follows Cl0p's established mass-exploitation-then-extortion pattern and has been added to CISA's KEV catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
