← nejvýznamnější zprávy · všechny zprávy

poslední zpráva

SPOJENO PŘES CVE KEV ✓ · ransomware EPSS 0.46

Clop created custom web shell for Windchill data theft attacks

A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]

Číst originál na BleepingComputer →

3 zprávy z 2 zdrojů · první CZ · EN/orig

PTC General Electric Philips výroba a průmysl US

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-12569 9.3 4.0 · PTC KEV ✓ 0.46

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.

Jak se o tom psalo 3

  1. · BleepingComputer US nadpis události

    Clop created custom web shell for Windchill data theft attacks

    A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]

  2. · BleepingComputer US

    Philips and GE investigating Clop ransomware data theft claims

    Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

  3. · Wiz Research US

    Cl0p Exploitation of PTC Windchill and FlexPLM Vulnerability (Campaign)

    The observed attack chain begins with reconnaissance against the FlexPLM WSDL endpoint, followed by exploitation of the information disclosure vulnerability and CVE-2026-12569, a deserialization flaw that enables unauthenticated remote code execution. Attackers deploy hex-name...