DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
CRITICAL#ransomware

Cl0p Actively Exploiting CVE-2026-12569 in PTC Windchill/FlexPLM — Manufacturing, Aerospace, Automotive Sectors Under Active Exfiltration

Cl0p affiliates (aka Lace Tempest, FIN11, Graceful Spider) are chaining a pre-auth FlexPLM WSDL information disclosure flaw with a critical unsafe deserialization bug in the Windchill login servlet (CVE-2026-12569, CVSS 9.3) to achieve unauthenticated RCE, drop hex-named JSP webshells under /Windchill/login/, and stage engineering IP for double-extortion. Ransom-ISAC confirmed four new C2 indicators as of July 22, and extortion emails with the subject 'Windchill PDMLink module serious data leak' are being mass-distributed from compromised internal accounts to hundreds of users per victim organization. PTC serves over 30,000 organizations worldwide — including 1,500+ FlexPLM customers in aerospace, defense, and automotive — and patches released June 17 remain widely unapplied; threat hunting should extend back to early June 2026.

PTC serves over 30,000 organizations worldwide — including 1,500+ FlexPLM customers in aerospace, defense, and automotive — and patches released June 17 remain widely unapplied; threat hunting should extend back to early June 2026.

This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the critical severity rating as a guide to prioritization within their environment.

For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.

STAY AHEAD OF THREATS
Daily intel briefs and IOC packages — delivered to your inbox the moment a new advisory drops.
SUBSCRIBE — $29/MO →
SHARE BRIEF:✕ Post on Xin Share on LinkedIn

RELATED ACTORS