logo

Clop ransomware targets Windchill, FlexPLM in data theft attacks

ID: 6e2e035b-069f-513a-aab6-39edb1aa715c

STIX ID: report--6e2e035b-069f-513a-aab6-39edb1aa715c

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Sergiu Gatlan

...
...

Clop (Cl0p) is actively exploiting a critical unsafe deserialization vulnerability (CVE-2026-12569, CVSS 9.3) in PTC Windchill and FlexPLM to achieve unauthenticated remote code execution, deploy JSP webshells, exfiltrate sensitive product data, and extort victims; PTC and CISA have issued advisories and emergency patching guidance while victims have received extortion emails from addresses such as [email protected].

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.