Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
ID: b7870c22-54f6-5963-96d1-02b60ebfb1f4
STIX ID: report--b7870c22-54f6-5963-96d1-02b60ebfb1f4
Feed Name: The Hacker News
Threat actors associated with Cl0p are actively exploiting a critical PTC Windchill/Windmill vulnerability (CVE-2026-12569, CVSS 9.3) chained with a FlexPLM pre-auth information-disclosure flaw to achieve unauthenticated RCE and deploy hex-named JSP web shells, enabling file-system enumeration, theft of engineering/design data, and double-extortion ransom demands; Ransom-ISAC, eCrime.ch and DEFUSED released a coordinated advisory and published four IoC IP addresses tied to the campaign, which has impacted manufacturing, automotive, aerospace, and retail organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
