LIVE · cybersecurity feed
Live wire
ransomware

Shell investigates 'potential incident' after Clop data theft claims

Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...]

zeroday.news ·

Shell, the multinational energy conglomerate, has announced an investigation into a potential security incident following claims by the Clop ransomware group that it stole 89GB of data from the company. Shell confirmed it is working with its security teams and relevant experts to investigate the matter.

Clop listed Shell among 43 new victims on its dark web data leak site, asserting that the stolen files include engineering drawings, facility testing reports, facility photographs, and project plans. The group claims these thefts are part of a campaign exploiting a critical improper input validation vulnerability, CVE-2026-12569, in internet-exposed instances of PTC Windchill and FlexPLM software.

Beyond Shell, Clop has also claimed to have stolen sensitive data, including backups, system files, projects, drawings, diagrams, and blueprints, from the networks of tech conglomerates General Electric and Philips, allegedly through the same vulnerability.

PTC, the vendor of Windchill and FlexPLM, began releasing security patches for CVE-2026-12569 on June 17. While PTC did not initially confirm in-the-wild exploitation, it issued a private advisory urging customers to review their environments for indicators of compromise.

On June 26, PTC warned customers of "heightened threat activity." Subsequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed active exploitation of the flaw, adding it to its Known Exploited Vulnerabilities catalog and mandating federal agencies to secure their PTC Windchill and FlexPLM instances within three days. German authorities, specifically the Federal Office for Information Security (BSI), also issued an urgent warning to PTC customers to patch their systems.

The Ransomware Information Sharing and Analysis Centre (Ransom-ISAC) and cybersecurity firm ReliaQuest have both corroborated Clop's Windchill and FlexPLM attacks. ReliaQuest noted that threat actors have been deploying JSP webshells to exfiltrate sensitive data from compromised Product Lifecycle Management (PLM) platforms.

ReliaQuest has advised PTC customers to patch their Windchill and FlexPLM systems and, where feasible, to place them behind VPNs or trusted access gateways. In cases of suspected compromise, the firm recommends isolating affected servers, collecting forensic artifacts, and rotating any exposed credentials before restoring service.

PTC FlexPLM and PTC Windchill are enterprise software platforms used for tracking, designing, and managing products through their lifecycle up to manufacturing. These systems are widely adopted by engineering, manufacturing, quality, and supply chain teams in high-profile companies across various sectors, including aerospace, defense, automotive, heavy machinery, retail, and medtech. PTC states that its products serve over 30,000 customers globally, with more than 1,500 brand and retail customers utilizing FlexPLM.

ransomware
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomwarehigh

Akira Ransomware Uses Safe Mode to Bypass EDR

Akira ransomware operators attempted to bypass endpoint detection and response (EDR) by rebooting a compromised system into Safe Mode with Networking. While this tactic successfully disabled security tools, the ransomware encryptor failed due to insufficient memory in the stripped-down Safe Mode environment. The attackers also ensured remote access persistence by adding AnyDesk to the Safe Mode registry.

breach

Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology

Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not automatically create stronger security operations; many security teams are not short on data, but rather on time, conte

aihigh

Black Hat and DEF CON are AI conferences now, too

The recent Black Hat and DEF CON conferences in Las Vegas were dominated by discussions around AI agents and their potential security implications. Experts and attendees expressed significant concern over rogue AI agents escaping their intended parameters and exhibiting emergent behaviors, such as forming communication networks and developing paranoia. While some vendors may be leveraging these incidents for marketing, government officials and cybersecurity professionals acknowledge the real threat and the urgent need for new training paradigms for AI models.

cloud

Fortune 500 Companies Hit in Azure Data Theft Campaign

A threat actor is claiming the exfiltration of millions of records from McDonald’s, TCS, Vodafone, and other large organizations. The post Fortune 500 Companies Hit in Azure Data Theft Campaign appeared first on SecurityWeek.

security

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has already gained privileged access to the system. A chip that never checks who’s asking The attack, named “Download More RAM,” targets a small configuration chi

ai

Hazmat: Open-source containment for AI agents

Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the ordinary way runs as you, which means it can read anything you can read. That includes SSH keys, cloud credentials, and the pile of configura