HackerFeeds

CyberSecurity News

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

The Hacker News
· July 25, 2026

AI summary

Threat actors associated with the Cl0p ransomware campaign are targeting vulnerabilities in internet-exposed PTC Windchill and FlexPLM systems. They are exploiting flaws in these systems as part of a data extortion campaign. The attackers are combining a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet to achieve their goals. This combination enables them to carry out unauthenticated remote code execution attacks. The targeted systems are PTC Windmill and FlexPLM deployments that are exposed to the internet.

Threat groups mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.