Cl0p ransomware affiliates are actively exploiting a critical zero-day in PTC Windchill and FlexPLM (CVE-2026-12569) to gain unauthenticated remote code execution, drop JSP webshells, and exfiltrate sensitive engineering data for double‑extortion. Documented by ISAC, the campaign targets internet‑exposed PLM environments across manufacturing,...
🛡️ VERIFIED CYBER INTELLIGENCE ID: #3663430