Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cl0p Ransomware Exploits PTC Software Vulnerabilities

Cl0p Ransomware Exploits PTC Software Vulnerabilities

Posted on July 25, 2026 By CWS

Cl0p Ransomware Targets PTC Software

The notorious Cl0p ransomware group, also known by aliases such as Chubby Scorpius and FIN11, has launched a new wave of attacks exploiting vulnerabilities in PTC’s Windchill and FlexPLM applications. These attacks are part of an escalating data extortion campaign targeting industries including manufacturing, automotive, aerospace, and retail.

New Exploits in PTC Windchill and FlexPLM

Threat actors have been exploiting a combination of a pre-authentication vulnerability in the FlexPLM WSDL endpoint and a server-side flaw in the Windchill login servlet. This technique enables them to execute unauthorized remote code and deploy JSP web shells within the Windchill login path. This coordinated advisory by Ransom-ISAC, eCrime.ch, and DEFUSED highlights the severity of the threat.

Upon breaching the systems, attackers engage in file system exploration, staging sensitive engineering and design data, and executing double extortion tactics. This involves not only data theft but also potential threats of releasing the data unless a ransom is paid, significantly impacting targeted sectors.

Critical Vulnerability CVE-2026-12569

The exploitation centers around CVE-2026-12569, a critical flaw in PTC Windchill with a CVSS score of 9.3. This vulnerability was recently added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, underscoring its critical nature. PTC has issued warnings to its customers about increased threat activities exploiting this vulnerability to install JSP web shells.

Security researchers Brandon Parsons, Corsin Camichel, and Simo Kohonen have detailed how this remote code execution (RCE) vulnerability is combined with a separate pre-authentication flaw in FlexPLM, adding another layer of risk for organizations using these software solutions.

Indicators of Compromise and Warnings

Ransom-ISAC has identified four IP addresses as indicators of compromise (IoCs), coinciding with those shared by PTC. These addresses are being used to detect and mitigate potential breaches. The extortion emails used in these attacks often originate from previously compromised accounts, and they are widespread, affecting hundreds of users within affected organizations.

Further analysis by ReliaQuest has confirmed the active exploitation of CVE-2026-12569 by Cl0p actors to execute unauthorized commands and exfiltrate sensitive data. Although the exact identities of the attackers remain undetermined, the methods align with prior Cl0p operations targeting enterprise software vulnerabilities.

Conclusion and Future Outlook

The Cl0p ransomware group continues to pose a significant threat by exploiting vulnerabilities in widely-used enterprise software. The group’s history of targeting security flaws for data theft and extortion emphasizes the need for organizations to strengthen cybersecurity measures and remain vigilant against potential threats. As these attacks evolve, continuous monitoring and prompt vulnerability patching are imperative to safeguard critical data assets.

The Hacker News Tags:Cl0p ransomware, CVE-2026-12569, cyber attacks, Cybersecurity, data extortion, data theft, enterprise security, FlexPLM, IoCs, PTC vulnerabilities, RCE, Threat Actors, unauthorized access, web shells, Windchill

Post navigation

Previous Post: Phishing Threats Evolve to Real-Time Insurance Account Hijacking
Next Post: DevMan RaaS Centralizes Cyber Operations and Affiliations

Related Posts

Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files The Hacker News
LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing The Hacker News
Detour Dog Caught Running DNS-Powered Malware Factory for Strela Stealer Detour Dog Caught Running DNS-Powered Malware Factory for Strela Stealer The Hacker News
Hugging Face AI Platform Breached by Autonomous AI Hugging Face AI Platform Breached by Autonomous AI The Hacker News
CloudZ Malware Exploits Phone Link for Credential Theft CloudZ Malware Exploits Phone Link for Credential Theft The Hacker News
FBI and Europol Dismantle Cybercrime Forum LeakBase FBI and Europol Dismantle Cybercrime Forum LeakBase The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Researcher Reveals Potential AI Model Jailbreak Technique
  • DevMan RaaS Centralizes Cyber Operations and Affiliations
  • Cl0p Ransomware Exploits PTC Software Vulnerabilities
  • Phishing Threats Evolve to Real-Time Insurance Account Hijacking
  • Fastjson Vulnerability Exploited in Active Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Researcher Reveals Potential AI Model Jailbreak Technique
  • DevMan RaaS Centralizes Cyber Operations and Affiliations
  • Cl0p Ransomware Exploits PTC Software Vulnerabilities
  • Phishing Threats Evolve to Real-Time Insurance Account Hijacking
  • Fastjson Vulnerability Exploited in Active Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark