[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:clop-linked-windchill-web-shell-decrypts-credentials-and-maps-engineering-data-mt1pqhdj":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":13,"action_required":16,"article_ids":17,"ioc_summary":19,"source_urls":20,"status":22,"expires_at":23,"created_at":24,"updated_at":25,"articles":26},"7cc9ed51-013e-444e-b2d8-3e01da939e63","Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data","clop-linked-windchill-web-shell-decrypts-credentials-and-maps-engineering-data-mt1pqhdj","Clop ransomware operators deployed a custom JSP web shell targeting PTC Windchill and FlexPLM servers, exploiting CVE-2026-12569 to decrypt stored credentials and exfiltrate engineering data. Any organization running vulnerable Windchill instances is at immediate risk of credential compromise, lateral movement, and enterprise-wide breach. The shell provides attackers direct access to proprietary designs, source code, and administrative credentials including LDAP passwords.","critical","advisory",[12],"CVE-2026-12569",[14,15],"PTC Windchill","FlexPLM","Immediately patch PTC Windchill and FlexPLM to the latest version addressing CVE-2026-12569. Scan all Windchill servers for JSP web shells in web directories. Force password reset for all Windchill and LDAP service accounts. Review recent Windchill access logs for suspicious activity and lateral movement indicators.",[18],"bf0a19fd-17d7-4193-8473-265954a4e260",null,[21],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fclop-linked-windchill-web-shell.html","archived","2026-08-22T16:06:26.823+00:00","2026-08-20T16:06:30.094317+00:00","2026-08-22T17:05:46.110238+00:00",[27],{"id":18,"title":6,"url":21}]