#2
The Hacker News
general
July 25, 2026 at 10:14 UTC
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
By [email protected] (The Hacker News)
AI Summary
Cl0p ransomware affiliates (tracked as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) are actively exploiting chained unauthenticated RCE vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments in a new data extortion campaign. The attack chain combines a pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint with a server-side vulnerability in the Windchill login servlet. Industrial organizations using these PLM platforms should immediately audit external exposure and apply available patches.
Relevance score: 87.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →