Clop (also known as Cl0p) is exploiting CVE-2026-12569 to attack Internet-exposed PTC Windchill and FlexPLM instances, using JSP web shells to steal sensitive product data in a new extortion campaign. The activity has prompted urgent patching and mitigation steps from PTC, CISA, and German authorities as the gang continues its long-running pattern of targeting enterprise platforms for data theft. #Clop #Cl0p #CVE-2026-12569 #PTCWindchill #PTCFlexPLM #CISA #BSI
Keypoints
- Clop is targeting exposed PTC Windchill and FlexPLM systems.
- The gang is exploiting CVE-2026-12569 for remote code execution.
- Attackers are deploying JSP web shells to exfiltrate sensitive data.
- PTC, CISA, and BSI urged customers to patch and review for compromise.
- Clop has a history of data theft campaigns against enterprise platforms.