A Chill in the Air: Cl0p Targets Windchill, Another Enterprise Software Product
ID: 99065ec6-8008-51cb-b595-2539f9608944
STIX ID: report--99065ec6-8008-51cb-b595-2539f9608944
Feed Name: Censys Blog
Threat Score
**Executive Summary:** Cl0p actors exploited a critical RCE (CVE-2026-12569) in PTC Windchill/FlexPLM in early June 2026 to target enterprise customers—potentially stealing engineering and manufacturing IP—and began extortion emails in July; Censys observed fewer than 100 Internet-exposed instances, 12 IOC IPs with rapid service churn, and new Cl0p contact domains (cryptohox.com, cypherhex.com), and recommends immediate patching and removal of Windchill from public exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
