LIVE · cybersecurity feed
Live wire
CVE-2026-12569critical

Cl0p Targets 40+ Organizations Through PTC Windchill Flaw

The Cl0p ransomware group has claimed responsibility for exploiting a critical vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM software, impacting over 40 organizations. The group is using a custom implant for data theft and extortion, demanding payment from victims. Several major companies, including Shell and Philips, are reportedly among the targeted entities, though most have only acknowledged awareness and are investigating.

zeroday.news ·

The Cl0p ransomware group claims to have compromised over 40 organizations by exploiting a critical vulnerability in PTC's Windchill and FlexPLM product lifecycle management (PLM) software. This vulnerability, identified as CVE-2026-12569, is a remote code execution (RCE) flaw with a CVSS score of 9.3, stemming from the deserialization of untrusted data. It affects all CPS versions and Windchill and FlexPLM releases prior to 11.0 M030.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this flaw to its Known Exploited Vulnerabilities (KEV) catalog in June, indicating active exploitation. German authorities reportedly issued direct warnings to organizations about impending attacks, suggesting the exploitation window was not covert.

According to security firm ReliaQuest, Cl0p deployed a sophisticated custom implant rather than a basic web shell. This implant functions as a comprehensive extortion platform, capable of mapping sensitive vault data, decrypting credentials stored in the Windchill keystore, and executing additional code within the application process via a custom Java class loader. This functionality effectively transforms the initial access into an extensive backdoor, facilitating lateral movement, ransomware deployment, or persistent access for prolonged periods.

The group's strategy mirrors its past campaigns against other enterprise software platforms like Oracle E-Business Suite, MOVEit, Cleo, and GoAnywhere. Cl0p exploits a single vulnerability in widely used enterprise software to target numerous companies, subsequently publishing the names of victims who refuse to pay a ransom.

Cl0p initially listed partial company names on its leak site, transitioning to full names starting August 12. The victim count has steadily increased since then. For each organization, the listings specify the type and approximate volume of stolen data, which ranges from a single gigabyte to several terabytes. The compromised data reportedly includes databases, project files, backups, engineering documents, blueprints, diagrams, corporate files, and images.

Prominent organizations named on Cl0p's leak site include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Largan Precision, a supplier of camera lenses for Apple devices. Notably, GE briefly appeared on the list before being removed, a move that often indicates either a ransom payment or ongoing negotiations. Shell, Philips, Fiserv, and GE have publicly acknowledged awareness of Cl0p's claims and stated they are investigating, though none have confirmed a significant breach at this time.

The targeting of PLM software is particularly significant because these systems are deeply embedded within manufacturing supply chains and contain sensitive engineering data that would be valuable to competitors or state-sponsored actors. Organizations utilizing Windchill or FlexPLM are strongly advised to prioritize checking for and patching this specific CVE.

ransomwareextortionvulnerabilityrcesupply chain
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

cisahigh

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

CISA has issued a directive for immediate patching of critical vulnerabilities affecting TrueConf software. The Head Mare hacktivist group is actively exploiting these flaws to distribute the PhantomCore malware. Organizations using TrueConf are urged to apply the necessary updates to prevent further compromise.

gitlab

GitLab 19.3 helps enterprises scale agentic development securely

GitLab's latest update, version 19.3, enhances security and control for enterprises scaling agentic software development. Key features include running GitLab Duo Agent Platform within dedicated single-tenant environments, allowing custom model integration, and keeping AI data within existing security boundaries. The release also introduces improved secrets management, bulk SAST false positive detection, and a Flow Creator Agent for simplified automation.

CVE-2026-69836high

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant's cloud-based identity and access management service. It was previously called Azure Active Directory

vulnerability

Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.

Secure Workload Software has five nasty flaws and even SaaS users have updates to install

finance

A $25 template helped scammers build hundreds of phantom bank domains

A phrase on a suspicious website turned into an investigation of phantom banks built to support scams, according to new research from Allure Security. Molly DeQuattro, the company’s VP of Operations, was reviewing a domain that resembled the brand of one of its financial services clients. The page carried none of that client’s branding. It presented an unrelated bank instead. One phrase caught her