View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Clop-linked actors target Windchill and FlexPLM for data theft

๐Ÿšจ ACTIVE EXPLOITATION

  • Clop-linked actors target Windchill and FlexPLM for engineering-data theft CVE-2026-12569 Clop-linked actors are stealing engineering data from Windchill and FlexPLM deployments.
    • PTC Windchill PDMLink and FlexPLM customers are affected, with 42 masked Clop listings linked to the campaign.
    • CVE-2026-12569 enables unauthenticated remote code execution; releases before 11.0 M030 are affected.
    • Attackers chain FlexPLM WSDL information disclosure with a Windchill login-servlet flaw.
    • They deploy hex-named JSP web shells under /Windchill/login/; observed indicators include X-windchill-req and flst.txt.
    • Stolen data includes projects, databases, CAD files, engineering drawings, backups and product documentation for extortion without observed encryption. ๐Ÿ“„ Source: ptc.com ยท ๐Ÿ“Ž Coverage: foresiet.com ยท ๐Ÿ‘ via @campuscodi@mastodon.social

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Spain arrests suspect accused of using AI face swaps to obtain digital certificates Spanish police arrested a suspect accused of using AI face swaps to obtain digital certificates.

    • Spanish individuals and businesses were targeted through a digital-certificate issuer in Spain.
    • The suspect allegedly made 38 attempts to impersonate 30 people and obtained certificates multiple times.
    • Real-time face-swapping, forged identity documents and altered photographs bypassed live video checks.
    • Colored spotlights simulated document holograms, while VPNs and more than 320 phone lines obscured the operation.
    • A brief face-swap processing delay exposed the suspect's real face to the verification camera. ๐Ÿ“„ Source: interior.gob.es ยท ๐Ÿ“Ž Coverage: theregister.com ยท ๐Ÿ‘ via @campuscodi@mastodon.social
  • CSS Attacks Against Webmail Can Steal Passwords and Tokens Researchers demonstrated CSS-only attacks that steal webmail credentials and authentication tokens.

    • Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail are affected by demonstrated attack chains.
    • The techniques can capture passwords, steal authentication tokens, hijack sessions, and manipulate connected AI tools.
    • Attackers exploit gaps between HTML/CSS sanitizers, browser parsing, and CSSOM mutations to cross email trust boundaries.
    • CSS-styled select controls can mimic password fields, while a Firefox timing quirk enables real-time keystroke capture through background requests.
    • A Firefox paste-handling race exposed 12-character Medium login tokens from Yahoo and AOL drafts; Gmail's image-set() bypass enabled Slack-token exfiltration through Claude Cowork. ๐Ÿ“„ Source: github.com ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via r/netsec

๐Ÿ”“ CVEs & KEV

  • Other: 18 CVEs (worst 9.4)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check