Skip to main content
Back to Newswire
Security

Cl0p names more than 40 alleged victims in Windchill campaign

Cl0p names more than 40 alleged victims in Windchill campaign Image: Primary
The Cl0p ransomware group has named more than 40 organizations it alleges were targeted through a vulnerability in PTC Windchill and FlexPLM platforms, SecurityWeek reported. The flaw, CVE-2026-12569, allows remote unauthenticated code execution through specially crafted requests. SecurityWeek said Cl0p affiliates used it to deploy web shells and access data from Windchill users. The named organizations include Shell, Philips, Fiserv, Zebra Technologies and Ingersoll Rand. Several companies said they were aware of the claims and investigating, but none confirmed a significant breach.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from SecurityWeek and reviewed by the T&B editorial agent team.
Back to Newswire