Afternoon Review in IT Security — July 26, 2026
The threat landscape continues to evolve rapidly as researchers and security teams grapple with critical vulnerabilities spanning manufacturing systems, development platforms, and identity infrastructure. Today's briefing covers active exploitation campaigns, newly published proof-of-concept exploits, regulatory enforcement actions, and emerging privilege escalation techniques that demand immediate attention from security practitioners across multiple sectors.
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Threat actors affiliated with the Cl0p ransomware campaign are actively exploiting vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments as part of an ongoing data extortion operation. The attackers chain a pre-authentication information disclosure vulnerability in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet to achieve unauthenticated remote code execution. This campaign represents a significant threat to manufacturing and product lifecycle management environments that rely on these widely deployed platforms.
The exploitation activity involves multiple infrastructure points, with investigators identifying several IP addresses associated with the attack infrastructure. Organizations running internet-facing instances of these products are strongly advised to assess their exposure and apply available security patches immediately. Source: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Security researcher Yuhang Wu at depthfirst has released a functional proof-of-concept exploit demonstrating remote code execution on unpatched GitLab 18.11.3 installations. The exploit allows an ordinary authenticated user to execute arbitrary commands with git privileges by committing two specially crafted Jupyter notebooks and requesting their diff comparison. Notably, the attack chain requires no administrator rights, continuous integration runner access, or victim interaction, significantly lowering the barrier to exploitation.
This disclosure highlights the importance of timely patching and the risks associated with misclassified security vulnerabilities in development infrastructure. Organizations operating self-managed GitLab instances should prioritize verification of their patch status and implement access controls to limit the blast radius of potential compromises. Source: Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Spain's Data Protection Authority Fines 23andMe Following Credential-Stuffing Breach
Spain's data protection authority (AEPD) has issued a significant fine following a credential-stuffing attack that exposed genetic data belonging to Spanish users of the 23andMe platform. The regulatory enforcement action underscores the serious consequences of inadequate authentication controls and the particular sensitivity of genetic information under data protection frameworks. The incident demonstrates how attackers continue to exploit weak credential hygiene across consumer-facing services, even those handling highly sensitive personal data.
This case reinforces the importance of implementing multi-factor authentication, monitoring for unauthorized access patterns, and maintaining robust incident response procedures for services that process sensitive personal information. Source: AEPD (Spain) - PS-00140-2025
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
Researchers H0j3n and Aniq Fakhrul have published a working exploit demonstrating a critical privilege escalation vulnerability in Active Directory Certificate Services. The flaw, designated Certighost, permits a low-privileged Active Directory user to obtain a certificate for a Domain Controller and subsequently authenticate as that machine. Since Domain Controller accounts possess directory replication rights, successful exploitation enables attackers to retrieve the krbtgt secret through DCSync operations, effectively compromising the entire Active Directory environment.
This vulnerability represents a severe threat to enterprise identity infrastructure and requires immediate patching across all affected systems. Organizations should prioritize assessment of their certificate services configurations and implement additional monitoring for suspicious certificate requests and Domain Controller authentication attempts. Source: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
The convergence of these threats—from supply chain manufacturing systems to development platforms, consumer data breaches, and enterprise identity infrastructure—underscores the need for comprehensive security strategies that address both technical vulnerabilities and operational resilience across all organizational systems.