Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
ReliaQuest has uncovered a sophisticated JavaServer Pages (JSP) web shell deployed by the Clop ransomware group following the exploitation of CVE-2026-12569, a…
ReliaQuest has uncovered a sophisticated JavaServer Pages (JSP) web shell deployed by the Clop ransomware group following the exploitation of CVE-2026-12569, a…
Windchill is a PLM software by PTC used for managing engineering data. It is vulnerable to CVE-2026-12569 and targeted by Clop's custom…
FlexPLM is a product lifecycle management solution by PTC, also vulnerable to CVE-2026-12569 and exploited in the same campaign.
Threat actors linked to the Cl0p ransomware group are actively exploiting vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments as part of…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability affecting PTC Windchill PDMlink and PTC…
PTC's Windchill and FlexPLM products are enterprise PLM solutions storing sensitive engineering data. They were exploited via CVE-2026-12569 to deploy a custom…
PTC Windchill and FlexPLM Improper Input Validation Vulnerability Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing…