Skip to main content
See every side of every news story
Published loading...Updated

Clop created custom web shell for Windchill data theft attacks

Summary by BleepingComputer
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]

7 Articles

I put it in context: Clop’s cyberattack is not an isolated incident. The cyberextortion group has exploited a zero-day at PTC Windchill to steal data from dozens of multinationals and press with threatening emails since mid-July. CVE-2026-12569 vulnerability: dates, patch and silence of the PTC company revealed the vulnerability CVE-2026-12569 on June 17 and published the patch the next day with initial compromise indicators. The failure, a remo…

SecurityBrief AsiaSecurityBrief Asia
+2 Reposted by 2 other sources

Clop-linked web shell hits Windchill in new exploit

Manufacturers face credential theft and engineering-data loss after a tailored Windchill web shell tied to Clop exploited CVE-2026-12569.

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in Melville, United States on Tuesday, August 18, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal