Digest
CRITICAL

Cl0p Affiliates Exploit PTC Windchill and FlexPLM for Data Extortion

Threat actors associated with the Cl0p ransomware group are exploiting vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments. The attack chain involves combining a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet. This allows unauthenticated remote code execution, leading to data extortion campaigns targeting sensitive information.

← Back to the feed

Trending Tags