A custom Java web shell linked to the Clop ransomware gang was built specifically to steal data from PTC Windchill and FlexPLM servers. Researchers say the malware can decrypt application credentials, search file repositories and retrieve files from compromised servers. Its design suggests that the operators understood Windchill’s internal APIs, database structure and storage system…
Philips and General Electric are investigating claims that the Clop ransomware group stole data from their systems. Philips says it contained an attempted compromise involving an internal server, while GE is still assessing the potential issue. Clop has listed both companies alongside Shell on its leak site, claiming the organisations were affected in attacks targeting…
The Clop ransomware group is reportedly targeting internet-exposed PTC Windchill and FlexPLM systems in a new data theft extortion campaign. Attackers are believed to be exploiting CVE-2026-12569, a critical vulnerability that can allow unauthenticated remote code execution on vulnerable Product Lifecycle Management platforms. Security researchers observed threat actors deploying JSP webshells after exploiting the flaw.…