Login
← All news

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

The Hacker News Security

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign. "Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet…

Read the full story on The Hacker News https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html
Attacks like this land on ordinary sites far more often than on chosen targets. If you would rather your site never became the story, CrockyHost hosting ships with daily backups, automatic updates and a firewall we manage.