Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison

    September 13, 2026

    This Week’s Awesome Tech Stories From Around the Web (Through September 12)

    September 13, 2026

    iPhone 18 Pro vs Google Pixel 11 Pro: iOS or Android?

    September 13, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»PTC Windchill Vulnerability Exploited in Ransomware Campaign
    PTC Windchill Vulnerability Exploited in Ransomware Campaign
    Cybersecurity

    PTC Windchill Vulnerability Exploited in Ransomware Campaign

    The Tech GuyBy The Tech GuyJuly 27, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    A Cl0p ransomware affiliate has been observed exploiting a critical-severity remote code execution (RCE) vulnerability in PTC’s product lifecycle management (PLM) platforms Windchill and FlexPLM.

    Advertisement

    Tracked as CVE-2026-12569 (CVSS score of 9.3), the security defect is described as a deserialization of untrusted data issue that can be exploited without authentication.

    Patched on June 17, the bug was flagged as exploited in the wild the next day, when PTC published indicators of compromise (IoCs). It was added to CISA’s KEV catalog at the end of June.

    Fresh warnings from ReliaQuest and Ransom-ISAC (in collaboration with eCrime.ch and Defused) show that the vulnerability is now exploited in the wild by a Cl0p affiliate.

    “The actor behind these attacks remains unconfirmed. However, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories,” ReliaQuest says.

    A detailed Ransom-ISAC advisory shows that the attackers have been chaining a “pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet” to achieve RCE and deploy JSP webshells.

    Advertisement. Scroll to continue reading.

    Following initial access, the hackers have been observed enumerating filesystems, staging data, and exfiltrating data for extortion.

    Starting July 20, the attackers have been targeting organizations across the aerospace, automotive, manufacturing, and retail/apparel sectors, Ransom-ISAC’s advisory reads.

    As part of the observed campaign, the threat actor has been sending extortion emails with a subject line “Windchill PDMLink module serious data leak” to hundreds of users within the impacted organizations.

    “As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign,” Ransom-ISAC says.

    Organizations are advised to apply PTC’s patches and to use previously published and newly shared IoCs to conduct threat hunting. They should also follow PTC’s remediation steps.

    Related: US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

    Related: Rockwell Patches Code Execution Flaws in Arena Simulation Software

    Related: Is Patching Dead? Vulnerability Management in the Post-Mythos Era

    Related: New Check Point Zero-Day Vulnerability Exploited in the Wild

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison

    September 13, 2026

    Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

    September 12, 2026

    BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

    September 12, 2026

    GitLab Vulnerability Exploited One Day After Disclosure

    September 12, 2026

    Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

    September 12, 2026

    Phishing Research Challenges Conventional Security Awareness Testing

    September 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison

    September 13, 2026

    This Week’s Awesome Tech Stories From Around the Web (Through September 12)

    September 13, 2026

    iPhone 18 Pro vs Google Pixel 11 Pro: iOS or Android?

    September 13, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.