Home / Jul 26, 2026 / Story
0
#2 The Hacker News general July 25, 2026 at 10:14 UTC

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

By [email protected] (The Hacker News)

AI Summary

Cl0p ransomware affiliates (tracked as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) are actively exploiting chained unauthenticated RCE vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments in a new data extortion campaign. The attack chain combines a pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint with a server-side vulnerability in the Windchill login servlet. Industrial organizations using these PLM platforms should immediately audit external exposure and apply available patches.

Relevance score: 87.0/100

# More from July 26