Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Elon Musk’s X Money is now available to Premium and Premium+ X subscribers

    July 29, 2026

    6 things you’re doing that are ruining your Roku

    July 29, 2026

    Samsung’s new foldables get the S26’s USB webcam mode

    July 29, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»PTC Windchill Vulnerability Exploited in Ransomware Campaign
    PTC Windchill Vulnerability Exploited in Ransomware Campaign
    Cybersecurity

    PTC Windchill Vulnerability Exploited in Ransomware Campaign

    The Tech GuyBy The Tech GuyJuly 27, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    A Cl0p ransomware affiliate has been observed exploiting a critical-severity remote code execution (RCE) vulnerability in PTC’s product lifecycle management (PLM) platforms Windchill and FlexPLM.

    Advertisement

    Tracked as CVE-2026-12569 (CVSS score of 9.3), the security defect is described as a deserialization of untrusted data issue that can be exploited without authentication.

    Patched on June 17, the bug was flagged as exploited in the wild the next day, when PTC published indicators of compromise (IoCs). It was added to CISA’s KEV catalog at the end of June.

    Fresh warnings from ReliaQuest and Ransom-ISAC (in collaboration with eCrime.ch and Defused) show that the vulnerability is now exploited in the wild by a Cl0p affiliate.

    “The actor behind these attacks remains unconfirmed. However, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories,” ReliaQuest says.

    A detailed Ransom-ISAC advisory shows that the attackers have been chaining a “pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet” to achieve RCE and deploy JSP webshells.

    Advertisement. Scroll to continue reading.

    Following initial access, the hackers have been observed enumerating filesystems, staging data, and exfiltrating data for extortion.

    Starting July 20, the attackers have been targeting organizations across the aerospace, automotive, manufacturing, and retail/apparel sectors, Ransom-ISAC’s advisory reads.

    As part of the observed campaign, the threat actor has been sending extortion emails with a subject line “Windchill PDMLink module serious data leak” to hundreds of users within the impacted organizations.

    “As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign,” Ransom-ISAC says.

    Organizations are advised to apply PTC’s patches and to use previously published and newly shared IoCs to conduct threat hunting. They should also follow PTC’s remediation steps.

    Related: US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

    Related: Rockwell Patches Code Execution Flaws in Arena Simulation Software

    Related: Is Patching Dead? Vulnerability Management in the Post-Mythos Era

    Related: New Check Point Zero-Day Vulnerability Exploited in the Wild

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe

    July 28, 2026

    Cyera Acquiring Oasis Security in $1 Billion Deal

    July 28, 2026

    Google Adopts New Threat Actor Naming System

    July 28, 2026

    For Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a Startup

    July 28, 2026

    New GitHub, PyPI Policies Boost Supply Chain Security

    July 27, 2026

    DentaQuest Data Breach Potentially Impacts Over 23 Million People

    July 27, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026326 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026204 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Elon Musk’s X Money is now available to Premium and Premium+ X subscribers

    July 29, 2026

    6 things you’re doing that are ruining your Roku

    July 29, 2026

    Samsung’s new foldables get the S26’s USB webcam mode

    July 29, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.