Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.

“Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Frame – Linux X server in Assembly

Frame – Linux X server in Assembly Source: Hacker News

Startup founders urge U.S. government not to shut off Chinese open weight AI

Startup founders urge U.S. government not to shut off Chinese open weight AI Source: Hacker News

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting