Close Menu
    What's Hot

    3 Clever Things You Can Do With an Old Amazon Kindle

    Live Updates: Hundreds of Thousands Flee as Fires Rage in Spain and France

    Bank of America: A Welcome Dividend Increase (NYSE:BAC)

    Facebook X (Twitter) Instagram
    Trending
    • 3 Clever Things You Can Do With an Old Amazon Kindle
    • Live Updates: Hundreds of Thousands Flee as Fires Rage in Spain and France
    • Bank of America: A Welcome Dividend Increase (NYSE:BAC)
    • Commonwealth Games: England cruise past Northern Ireland to open netball campaign as Scotland fall to New Zealand | Netball News
    • Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
    • Troy Jackson Picked to Replace Platner as Democratic Nominee in Maine Senate Race
    • One fallen power line exposed a growing AI data center problem. Here’s how to fix it.
    • Meet the ultimate Google Photos power-up
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

    adminBy adminJuly 25, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 25, 2026Vulnerability / Ransomware

    Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

    Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.

    “Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling unauthenticated remote code execution and deployment of hex-named JSP web shells under /Windchill/login/,” according to a new coordinated advisory released by Ransom-ISAC along with eCrime.ch and DEFUSED.

    Upon gaining an initial foothold, the attackers have been found to conduct file system enumeration, stage engineering/design data, and ultimately carry out double extortion data theft. Targets of the campaign include manufacturing, automotive, aerospace, and retail sectors.

    Cybersecurity

    It’s suspected that threat actors are exploiting CVE-2026-12569 (CVSS score: 9.3), a critical security flaw in PTC Windmill that was added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog late last month.

    In an advisory, PTC warned customers that it had “received continued reports of heightened threat activity,” adding that unknown attackers are exploiting the vulnerability to deploy JSP web shells against susceptible systems.

    “In the observed intrusions, this RCE is chained with a separate pre-authentication information-disclosure defect in the FlexPLM WSDL endpoint (CVSS v3.1 7.5) to enable unauthenticated exploitation,” researchers Brandon Parsons, Corsin Camichel, and Simo Kohonen said.

    Ransom-ISAC has shared four IP addresses as indicators of compromise (IoCs), all of which match those shared by PTC –

    • 216.152.148.54
    • 216.152.151.204
    • 104.243.35.63
    • 5.180.41.35

    The extortion emails appear to originate from previously compromised accounts and are sent to hundreds of users within an impacted organization, along with ways to contact the Cl0p ransomware crew.

    Cybersecurity

    In a separate post on X, ReliaQuest said it observed threat actors actively exploiting CVE-2026-12569 to facilitate “unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration.”

    “The actor behind these attacks remains unconfirmed. However, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories,” it added.

    The Cl0p gang has a storied history of going after security flaws in widely-used enterprise products to break into target organizations for data theft and extortion attacks. Previous campaigns mounted by the group have weaponized file transfer appliances, including those from Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer, as well as a vulnerability in Oracle E-Business Suite.

    affiliates Cl0p FlexPLM InternetExposed PTC RCE Target Unauthenticated Windchill
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleTroy Jackson Picked to Replace Platner as Democratic Nominee in Maine Senate Race
    Next Article Commonwealth Games: England cruise past Northern Ireland to open netball campaign as Scotland fall to New Zealand | Netball News
    admin
    • Website

    Related Posts

    Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

    July 25, 2026

    CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

    July 25, 2026

    Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

    July 25, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    3 Clever Things You Can Do With an Old Amazon Kindle

    Live Updates: Hundreds of Thousands Flee as Fires Rage in Spain and France

    Bank of America: A Welcome Dividend Increase (NYSE:BAC)

    Commonwealth Games: England cruise past Northern Ireland to open netball campaign as Scotland fall to New Zealand | Netball News

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by