bleeping-computer · Crawled Jul 24, 2026
Clop ransomware targets Windchill, FlexPLM in data theft attacks
1 IoCs
Read original article ↗
AI Summary
The Clop ransomware gang is conducting a new data theft extortion campaign by exploiting a critical vulnerability, CVE-2026-12569, in Internet-exposed PTC Windchill and FlexPLM instances. The flaw allows unauthenticated remote code execution, enabling attackers to deploy JSP webshells for data exfiltration. Organizations in high-risk sectors such as aerospace, defense, and manufacturing are targeted, with Clop using the email [email protected] for extortion demands.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | cryptohox[.]com | Details → |