Find notable cyber news and cases, enriched with sources, timelines, and signals.

Clop Internet-exposed Windchill and FlexPLM data theft extortion campaign

Campaign
First reported
Last updated
Happening score
H score 55
2 unique sources, 2 articles

Summary

Hide ▲

The Cl0p campaign is targeting internet-exposed PTC Windchill and FlexPLM deployments in a data extortion operation, with CVE-2026-12569 enabling unauthenticated remote code execution and JSP web shell deployment. Researchers said the attackers chain a FlexPLM WSDL information disclosure with a flaw in the Windchill login servlet, then enumerate file systems, stage engineering and design data, and steal sensitive product data. The activity has hit manufacturing, automotive, aerospace, and retail sectors, while PTC issued patches and CISA added the flaw to its Known Exploited Vulnerabilities catalog. Companies have also received extortion emails from [email protected].

Related Happenings

IT services firm in South Asia data exposed after Spirals breach

Data Leak
H score31 First: 16.07.2026 13:00 Last: 16.07.2026 13:00 Sources 1

About this happening: Spirals stole data from an IT services firm in South Asia, creating extortion leverage and a threat of public exposure. The intrusion moved from initial access to...

CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server

Public Sector Action
H score35 First: 26.06.2026 22:43 Last: 26.06.2026 22:43 Sources 1

About this happening: CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...

PTC Windchill PDMlink and PTC FlexPLM actively exploited RCE (CVE-2026-12569)

Vulnerability
H score43 First: 26.06.2026 15:31 Last: 26.06.2026 15:31 Sources 1

How related: "In the observed intrusions, this RCE is chained with a separate pre-authentication information-disclosure defect in the FlexPLM WSDL endpoint (CVSS v3.1 7.5) to enable unauthenticated exploitation," researchers Brandon Parsons, Corsin Camichel, and Simo Kohonen said.

About this happening: CVE-2026-12569 is a critical vulnerability in PTC Windchill and PTC FlexPLM that has been actively exploited for unauthenticated remote code execution and...

Latest development: 24.07.2026 10:36

Clop (Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a data theft extortion campaign, reportedly exploiting CVE-2026-12569 to obtain unauthenticated remote code execution and deploy JSP web shells for sensitive product data exfiltration. Companies have also begun receiving extortion emails from [email protected], and ReliaQuest says threat actors are actively exploiting the flaw against PTC Windchill and FlexPLM.

CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM

Public Sector Action
H score46 First: 26.06.2026 15:31 Last: 26.06.2026 15:31 Sources 1

About this happening: CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...

2025 Automotive carmakers ransomware surge

Trend
H score34 First: 16.04.2026 11:35 Last: 16.04.2026 11:35 Sources 1

About this happening: In 2025, ransomware became the fastest-growing and most disruptive threat to automotive carmakers, accounting for 44% of attacks and more than doubling over th...

Timeline

  1. 24.07.2026 10:36 1 articles · 13d ago

    PTC releases patches and remediation guidance for CVE-2026-12569

    Mitigation Patch Update

    PTC began releasing security patches for CVE-2026-12569 affecting PTC Windchill and FlexPLM and issued private remediation guidance urging customers to review their environments for indicators of compromise.

    Show sources
  2. 24.07.2026 10:36 1 articles · 13d ago

    CISA adds CVE-2026-12569 to the Known Exploited Vulnerabilities catalog

    Legal Policy Action Update

    After PTC warned customers of heightened threat activity, CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to secure affected PTC Windchill and FlexPLM instances within three days.

    Show sources
  3. 24.07.2026 10:36 3 articles · 13d ago

    Internet-exposed Windchill and FlexPLM instances face active exploitation and extortion emails

    Initial Disclosure

    ReliaQuest observed threat actors actively exploiting CVE-2026-12569 against Internet-exposed PTC Windchill and FlexPLM, with unauthenticated remote code execution enabling JSP web shell deployment and sensitive product data exfiltration. Companies also began receiving extortion emails from [email protected], and the observed tradecraft shares characteristics with prior Cl0p campaigns.

    Show sources