logo

Clop gang targets Windchill, FlexPLM in data theft attacks

ID: 52a0ff95-d5d1-515f-8f12-164164155870

STIX ID: report--52a0ff95-d5d1-515f-8f12-164164155870

Feed Name: DataBreaches.Net

Threat Score
78/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Dissent

...
...

Clop (Cl0p) is exploiting a critical input-validation flaw (CVE-2026-12569) in Internet-exposed PTC Windchill and FlexPLM instances, deploying JSP webshells to exfiltrate sensitive data and conduct data-extortion operations against affected organizations, according to ReliaQuest and reporting by BleepingComputer.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.