A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]
The observed attack chain begins with reconnaissance against the FlexPLM WSDL endpoint, followed by exploitation of the information disclosure vulnerability and CVE-2026-12569, a deserialization flaw that enables unauthenticated remote code execution. Attackers deploy hex-name...