As cited
Citation snapshot as of .
ransomware
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Cl0p-affiliated threat actors are exploiting unauthenticated remote code execution (RCE) vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments. The attackers chain pre-authentication information disclosure in FlexPLM with server-side flaws in Windchill's login servlet to gain unauthorized access. This activity is part of an active data extortion campaign.
Why it matters: Organizations running PTC Windchill or FlexPLM with internet exposure face immediate risk of compromise by a known ransomware operator; patching or restricting network access to these systems should be prioritized today.
- Source published
- First seen by Cybersecurity Tracker