The Cl0p ransomware group has claimed responsibility for exploiting a critical vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM software, impacting over 40 organizations. The group is using a custom implant for data theft and extortion, demanding payment from victims. Several major companies, including Shell and Philips, are reportedly among the targeted entities, though most have only acknowledged awareness and are investigating.

The Cl0p ransomware group claims to have compromised over 40 organizations by exploiting a critical vulnerability in PTC's Windchill and FlexPLM product lifecycle management (PLM) software. This vulnerability, identified as CVE-2026-12569, is a remote code execution (RCE) flaw with a CVSS score of 9.3, stemming from the deserialization of untrusted data. It affects all CPS versions and Windchill and FlexPLM releases prior to 11.0 M030.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this flaw to its Known Exploited Vulnerabilities (KEV) catalog in June, indicating active exploitation. German authorities reportedly issued direct warnings to organizations about impending attacks, suggesting the exploitation window was not covert.
According to security firm ReliaQuest, Cl0p deployed a sophisticated custom implant rather than a basic web shell. This implant functions as a comprehensive extortion platform, capable of mapping sensitive vault data, decrypting credentials stored in the Windchill keystore, and executing additional code within the application process via a custom Java class loader. This functionality effectively transforms the initial access into an extensive backdoor, facilitating lateral movement, ransomware deployment, or persistent access for prolonged periods.
The group's strategy mirrors its past campaigns against other enterprise software platforms like Oracle E-Business Suite, MOVEit, Cleo, and GoAnywhere. Cl0p exploits a single vulnerability in widely used enterprise software to target numerous companies, subsequently publishing the names of victims who refuse to pay a ransom.
Cl0p initially listed partial company names on its leak site, transitioning to full names starting August 12. The victim count has steadily increased since then. For each organization, the listings specify the type and approximate volume of stolen data, which ranges from a single gigabyte to several terabytes. The compromised data reportedly includes databases, project files, backups, engineering documents, blueprints, diagrams, corporate files, and images.
Prominent organizations named on Cl0p's leak site include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Largan Precision, a supplier of camera lenses for Apple devices. Notably, GE briefly appeared on the list before being removed, a move that often indicates either a ransom payment or ongoing negotiations. Shell, Philips, Fiserv, and GE have publicly acknowledged awareness of Cl0p's claims and stated they are investigating, though none have confirmed a significant breach at this time.
The targeting of PLM software is particularly significant because these systems are deeply embedded within manufacturing supply chains and contain sensitive engineering data that would be valuable to competitors or state-sponsored actors. Organizations utilizing Windchill or FlexPLM are strongly advised to prioritize checking for and patching this specific CVE.



On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs