:

CLOP RANSOMWARE TARGETS PTC SOFTWARE IN DATA THEFT

SECURITY DESK1 MIN READ
FRI, JUL 24, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The Clop ransomware gang is exploiting vulnerabilities in PTC Windchill and FlexPLM platforms, targeting internet-exposed instances to steal data and extort victims.

The Clop ransomware operation (also tracked as Cl0p) has launched a focused campaign against PTC Windchill and FlexPLM users. Both products manage product lifecycle data, making them high-value targets for industrial espionage and extortion. Windchill serves as a product lifecycle management system widely used across manufacturing and engineering sectors. FlexPLM handles similar functions with emphasis on flexibility and integration. The attacks leverage publicly accessible instances that lack proper security controls. Clop's approach follows its established pattern: exfiltrate sensitive data, then demand payment under threat of public disclosure. PTC has not publicly confirmed the vulnerability being exploited. Organizations running these platforms should immediately audit their network exposure, apply available patches, and review access logs for suspicious activity. The threat actors have previously targeted similar enterprise software to access customer intellectual property and confidential manufacturing data.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Russian state-sponsored group Laundry Bear is targeting organizations running Zimbra Collaboration email servers by combining phishing attacks with exploitation of a patched vulnerability. CISA has issued a warning about the campaign.

3H AGOAI Desk

The 2026 FIFA World Cup venues across the US, Canada, and Mexico will implement extensive surveillance systems including face recognition and anti-drone technology. Fans attending matches will be subject to unprecedented monitoring.

3H AGOIndustry Desk

A new remote access trojan called Dolphin X leverages AI to profile and score infected users, enabling cybercriminals to prioritize high-value victims for exploitation.

6H AGOAI Desk

A race condition vulnerability in the Linux kernel's XFS filesystem allows local attackers to overwrite protected files and gain root privileges. The flaw, tracked as CVE-2026-64600, has remained unpatched for nine years.

9H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.