The Clop ransomware gang is actively targeting Internet-exposed instances of PTC Windchill and FlexPLM. They are exploiting a critical improper input validation vulnerability, identified as CVE-2026-12569, to conduct data theft and extortion campaigns.
ReliaQuest reported that Clop operators are deploying JSP webshells after exploiting CVE-2026-12569. This vulnerability, rated CVSS 9.3, enables unauthenticated remote code execution, allowing attackers to exfiltrate sensitive product data from compromised Product Lifecycle Management (PLM) platforms. The tradecraft observed shares characteristics with previous Clop campaigns targeting enterprise applications.
Companies have begun receiving extortion emails from the Clop gang, using new email addresses like support@cryptohox.com. In response to the active exploitation, PTC started releasing security patches for CVE-2026-12569 on June 17 and issued remediation guidance. The Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog, mandating U.S. federal agencies to secure their systems within three days. German authorities also issued urgent warnings to PTC customers.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The Clop ransomware group is exploiting a critical vulnerability (CVE-2026-12569) in PTC Windchill and FlexPLM to exfiltrate data from targeted companies. This exploitation has led to extortion campaigns and prompted urgent warnings from cybersecurity agencies and authorities.