CyberSecurity News
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
AI summary
Threat actors associated with the Cl0p ransomware campaign are targeting vulnerabilities in internet-exposed PTC Windchill and FlexPLM systems. They are exploiting flaws in these systems as part of a data extortion campaign. The attackers are combining a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet to achieve their goals. This combination enables them to carry out unauthenticated remote code execution attacks. The targeted systems are PTC Windmill and FlexPLM deployments that are exposed to the internet.
Threat groups mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

