By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Cl0p Exploits PTC Software for Data Extortion

Threat actors affiliated with the Cl0p ransomware campaign are actively exploiting vulnerabilities in internet-exposed deployments of PTC Windchill and FlexPLM software. This new data extortion campaign leverages a chain of exploits that allows for unauthenticated remote code execution (RCE).
The attackers first exploit a pre-authentication information disclosure vulnerability found in the FlexPLM WSDL endpoint. This initial compromise is then chained with a server-side flaw present in the Windchill login servlet. Successful exploitation of this sequence grants attackers the ability to execute arbitrary code on the targeted servers without prior authentication.
This exploitation method allows threat actors to gain unauthorized access to sensitive data stored within these PTC software instances. The Cl0p group, also known by various aliases including Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest, has a history of targeting enterprise software for large-scale data breaches and subsequent extortion. The group's modus operandi typically involves exfiltrating data from compromised organizations and then demanding ransom payments to prevent its public release.
The specific vulnerabilities being exploited have not been publicly disclosed by security researchers, but the attack vector targets widely used industrial software. PTC Windchill and FlexPLM are commonly used in product lifecycle management and engineering sectors, suggesting that organizations in manufacturing, automotive, and aerospace industries may be at increased risk. The unauthenticated nature of the RCE makes these deployments particularly vulnerable, as attackers do not need any prior access or credentials to initiate the exploit.
This campaign highlights the ongoing threat posed by ransomware groups targeting supply chain software and industrial control systems. Organizations utilizing PTC Windchill and FlexPLM are advised to review their security configurations, ensure all systems are patched with the latest security updates, and implement robust network segmentation and monitoring to detect and prevent such attacks.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.