Hackers are exploiting a critical vulnerability recently patched in PTC Windchill and FlexPLM, two product lifecycle management solutions used by organizations across a range of industries, including defense, aerospace, automotive, medical, electronics, industrial machinery, and consumer goods.
The vulnerability, tracked as to warn customers that it has received reports of heightened threat activity. The update included new indicators of compromise that suggest attackers are deploying web shells — backdoor web scripts — on compromised instances. On the same day the US Cybersecurity and Infrastructure Security Agency (CISA) in person to warn about a different zero-day vulnerability in Windchill that they had information attackers were planning to exploit.
The German Federal Office for Information Security (BSI) alerted companies about this new vulnerability as well, stressing it had reliable information about impending cyberattacks, the Heise media group reported.
PTC Windchill was first released 28 years ago and has more than 1.5 million users around the world, including companies such as BMW, Lockheed Martin, Boeing, and NVIDIA. PTC FlexPLM is a variant specifically designed for the retail, footwear, apparel, and consumer products industries.
SOCIAL SHARE CARD GENERATOR