The Clop ransomware gang is exploiting vulnerabilities in PTC Windchill and FlexPLM platforms, targeting internet-exposed instances to steal data and extort victims.
The Clop ransomware operation (also tracked as Cl0p) has launched a focused campaign against PTC Windchill and FlexPLM users. Both products manage product lifecycle data, making them high-value targets for industrial espionage and extortion.
Windchill serves as a product lifecycle management system widely used across manufacturing and engineering sectors. FlexPLM handles similar functions with emphasis on flexibility and integration.
The attacks leverage publicly accessible instances that lack proper security controls. Clop's approach follows its established pattern: exfiltrate sensitive data, then demand payment under threat of public disclosure.
PTC has not publicly confirmed the vulnerability being exploited. Organizations running these platforms should immediately audit their network exposure, apply available patches, and review access logs for suspicious activity. The threat actors have previously targeted similar enterprise software to access customer intellectual property and confidential manufacturing data.
Two Nigerian men have been extradited to the U.S. and charged in connection with sextortion schemes that led to the deaths of two minors in Mississippi and North Carolina.
Threat actors are exploiting a vulnerability chain in Microsoft SharePoint to execute arbitrary code on unpatched servers. Defused has confirmed attackers are leveraging proof-of-concept exploits in the wild.
Hackers have claimed to steal millions of patient records from McKesson, the major U.S. healthcare distributor. The company acknowledged the breach and warned of potential service disruptions.
Artificial intelligence is becoming adept at finding and patching software vulnerabilities, potentially undermining governments' ability to deploy spyware and hacking tools. The development could spark renewed pressure for backdoors in encrypted devices.