Cl0p Targets Internet-Exposed Windchill Servers in Global Engineering Data-Theft Campaign
ID: 2e9536c8-ff51-5d24-8e85-59359426e003
STIX ID: report--2e9536c8-ff51-5d24-8e85-59359426e003
Feed Name: GBHackers
Cl0p affiliates are actively exploiting a critical deserialization vulnerability (CVE-2026-12569, CVSS 9.8) in PTC Windchill (and chaining a FlexPLM WSDL disclosure) to achieve unauthenticated RCE, deploy hex‑named JSP webshells, enumerate and exfiltrate engineering/product design data, and run an extortion campaign against manufacturing, automotive, aerospace, and retail/apparel organizations; the report includes IOCs (IPs, SHA‑256 hash, malicious header, webshell path patterns), references to PTC patches and NVD/CISA advisories, and recommends immediate threat hunting and patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
