Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Dango Blockchain to Shut Down, Halt Perp DEX Trading

    July 25, 2026

    Wisconsin after-school programs lose thousands as child care funding ends

    July 25, 2026

    ‘Elephants in the Fog’: After Cannes Win, Nepal’s Queer Cinema Gets Boost

    July 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Dango Blockchain to Shut Down, Halt Perp DEX Trading
    • Wisconsin after-school programs lose thousands as child care funding ends
    • ‘Elephants in the Fog’: After Cannes Win, Nepal’s Queer Cinema Gets Boost
    • Did Trump collapse while trying to get into vehicle?
    • Former top US food safety official says Trump’s handling of cyclospora is ‘catastrophic’ | Trump administration
    • Record-breaking wildfires burned nearly 100,000 hectares in France, interior minister says – POLITICO
    • Home Office rejects Palestinian Jerusalemite woman’s UK visa but approves husband’s | Home Office
    • Samsung’s new Ultra foldable is impressive, but I’d pay close attention to this model
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, July 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 25, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJul 25, 2026Vulnerability / Ransomware

    Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.

    “Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling unauthenticated remote code execution and deployment of hex-named JSP web shells under /Windchill/login/,” according to a new coordinated advisory released by Ransom-ISAC along with eCrime.ch and DEFUSED.

    Upon gaining an initial foothold, the attackers have been found to conduct file system enumeration, stage engineering/design data, and ultimately carry out double extortion data theft. Targets of the campaign include manufacturing, automotive, aerospace, and retail sectors.

    Cybersecurity

    It’s suspected that threat actors are exploiting CVE-2026-12569 (CVSS score: 9.3), a critical security flaw in PTC Windmill that was added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog late last month.

    In an advisory, PTC warned customers that it had “received continued reports of heightened threat activity,” adding that unknown attackers are exploiting the vulnerability to deploy JSP web shells against susceptible systems.

    “In the observed intrusions, this RCE is chained with a separate pre-authentication information-disclosure defect in the FlexPLM WSDL endpoint (CVSS v3.1 7.5) to enable unauthenticated exploitation,” researchers Brandon Parsons, Corsin Camichel, and Simo Kohonen said.

    Ransom-ISAC has shared four IP addresses as indicators of compromise (IoCs), all of which match those shared by PTC –

    • 216.152.148.54
    • 216.152.151.204
    • 104.243.35.63
    • 5.180.41.35

    The extortion emails appear to originate from previously compromised accounts and are sent to hundreds of users within an impacted organization, along with ways to contact the Cl0p ransomware crew.

    Cybersecurity

    In a separate post on X, ReliaQuest said it observed threat actors actively exploiting CVE-2026-12569 to facilitate “unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration.”

    “The actor behind these attacks remains unconfirmed. However, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories,” it added.

    The Cl0p gang has a storied history of going after security flaws in widely-used enterprise products to break into target organizations for data theft and extortion attacks. Previous campaigns mounted by the group have weaponized file transfer appliances, including those from Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer, as well as a vulnerability in Oracle E-Business Suite.

    Affiliates Cl0p FlexPLM InternetExposed PTC RCE Target unauthenticated Windchill
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

    CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

    Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

    Europol flags 4,340 URLs for removal in ‘The Com’ crackdown

    Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

    Microsoft blames massive Microsoft 365 outage on maintenance bug

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Dango Blockchain to Shut Down, Halt Perp DEX Trading

    July 25, 2026

    Wisconsin after-school programs lose thousands as child care funding ends

    July 25, 2026

    ‘Elephants in the Fog’: After Cannes Win, Nepal’s Queer Cinema Gets Boost

    July 25, 2026

    Did Trump collapse while trying to get into vehicle?

    July 25, 2026
    Latest Posts

    Trump slaps 50% tariffs on Canada and Carney vows to ‘intensify’ trade talks

    July 21, 2026

    How Two Brothers Dug for Dead Relatives: With a Shovel and a Kitchen Knife

    July 21, 2026

    Chile floods: Towns evacuated following heavy rain in Coquimbo

    July 21, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Dango Blockchain to Shut Down, Halt Perp DEX Trading

    July 25, 2026

    Wisconsin after-school programs lose thousands as child care funding ends

    July 25, 2026

    ‘Elephants in the Fog’: After Cannes Win, Nepal’s Queer Cinema Gets Boost

    July 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.