CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 3213

As cited

Citation snapshot as of .

ransomware

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Cl0p-affiliated threat actors are exploiting unauthenticated remote code execution (RCE) vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments. The attackers chain pre-authentication information disclosure in FlexPLM with server-side flaws in Windchill's login servlet to gain unauthorized access. This activity is part of an active data extortion campaign.

Why it matters: Organizations running PTC Windchill or FlexPLM with internet exposure face immediate risk of compromise by a known ransomware operator; patching or restricting network access to these systems should be prioritized today.

Source published
First seen by Cybersecurity Tracker

Source attribution