Cl0p industrialise ses attaques via PTC Windchill
A critical vulnerability in PTC Windchill and FlexPLM has been exploited by the Cl0p group, leading to a widespread campaign targeting nearly 50 international companies, including Philips, Shell, Fiserv, and GE. The vulnerability (CVE-2026-12569) allows for remote code execution without authorization, and Cl0p appears to be leveraging a repeatable attack model, exploiting a common technology across multiple organizations to maximize its impact. While the exact scope of data exfiltration remains unclear, the group is claiming to have stolen significant volumes of data from these victims.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data