๐จ ACTIVE EXPLOITATION
- Clop-linked actors target Windchill and FlexPLM for engineering-data theft
CVE-2026-12569Clop-linked actors are stealing engineering data from Windchill and FlexPLM deployments.- PTC Windchill PDMLink and FlexPLM customers are affected, with 42 masked Clop listings linked to the campaign.
- CVE-2026-12569 enables unauthenticated remote code execution; releases before 11.0 M030 are affected.
- Attackers chain FlexPLM WSDL information disclosure with a Windchill login-servlet flaw.
- They deploy hex-named JSP web shells under /Windchill/login/; observed indicators include X-windchill-req and flst.txt.
- Stolen data includes projects, databases, CAD files, engineering drawings, backups and product documentation for extortion without observed encryption. ๐ Source: ptc.com ยท ๐ Coverage: foresiet.com ยท ๐ via @campuscodi@mastodon.social
๐ต๏ธ RESEARCH & DEEP DIVES
-
Spain arrests suspect accused of using AI face swaps to obtain digital certificates Spanish police arrested a suspect accused of using AI face swaps to obtain digital certificates.
- Spanish individuals and businesses were targeted through a digital-certificate issuer in Spain.
- The suspect allegedly made 38 attempts to impersonate 30 people and obtained certificates multiple times.
- Real-time face-swapping, forged identity documents and altered photographs bypassed live video checks.
- Colored spotlights simulated document holograms, while VPNs and more than 320 phone lines obscured the operation.
- A brief face-swap processing delay exposed the suspect's real face to the verification camera. ๐ Source: interior.gob.es ยท ๐ Coverage: theregister.com ยท ๐ via @campuscodi@mastodon.social
-
CSS Attacks Against Webmail Can Steal Passwords and Tokens Researchers demonstrated CSS-only attacks that steal webmail credentials and authentication tokens.
- Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail are affected by demonstrated attack chains.
- The techniques can capture passwords, steal authentication tokens, hijack sessions, and manipulate connected AI tools.
- Attackers exploit gaps between HTML/CSS sanitizers, browser parsing, and CSSOM mutations to cross email trust boundaries.
- CSS-styled select controls can mimic password fields, while a Firefox timing quirk enables real-time keystroke capture through background requests.
- A Firefox paste-handling race exposed 12-character Medium login tokens from Yahoo and AOL drafts; Gmail's image-set() bypass enabled Slack-token exfiltration through Claude Cowork. ๐ Source: github.com ยท ๐ Coverage: thehackernews.com ยท ๐ via r/netsec
๐ CVEs & KEV
- Other: 18 CVEs (worst 9.4)