Cl0p has publicly named more than 40 organizations allegedly hit in a campaign that abused CVE-2026-12569 in PTC Windchill and FlexPLM, using web shells and a custom implant to steal data. The stolen information reportedly includes databases, engineering documents, backups, and other sensitive files, with victims ranging from Shell and Philips to Fiserv and Zebra Technologies. #Cl0p #CVE-2026-12569 #PTC #Windchill #FlexPLM #Shell #Philips #Fiserv #ZebraTechnologies
Keypoints
- Cl0p named more than 40 alleged victims from the Windchill and FlexPLM campaign.
- The attacks exploited CVE-2026-12569, an improper input validation flaw in PTC software.
- The vulnerability allows remote, unauthenticated code execution through specially crafted requests.
- Cl0p used web shells and a custom implant to steal data and gain persistent access.
- Reported victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Largan Precision.
Read More: https://www.securityweek.com/cl0p-ransomware-group-names-over-40-victims-of-ptc-windchill-campaign/