🚨 ACTIVE EXPLOITATION
- Clop ransomware exploits PTC Windchill and FlexPLM in data theft attacks — BleepingComputer
Clop ransomware gang is exploiting vulnerabilities in PTC Windchill and FlexPLM to steal data.- Targets PTC Windchill and FlexPLM Product Lifecycle Management (PLM) platforms used by engineering and manufacturing sectors
- Exploits critical unsafe deserialization vulnerability CVE-2026-12569 allowing unauthenticated remote code execution
- Deploys JSP webshells for remote command execution and exfiltration of sensitive product data
- Extortion emails sent from support@cryptohox.com linked to Clop gang's new campaign
- PTC released patches starting June 17, 2026; CISA and German BSI issued urgent warnings and mitigation orders
🕵️ RESEARCH & DEEP DIVES
-
UAC-0099 group uses fake Notepad++ plugin to deliver MATCHBOIL.V2 malware — The Hacker News
UAC-0099 threat actors deploy MATCHBOIL.V2 malware via a fake Notepad++ plugin.- Targets Windows users via a fake Notepad++ plugin bundled with legitimate Notepad++ 8.8.3
- Delivered through phishing emails with image attachments linking to a ZIP archive containing VBScript
- VBScript downloads a decoy PDF and silently extracts malicious payloads including a DLL plugin and WinRAR executable
- Malicious DLL (LUNCHPOKE) unpacks and runs BURNYBEAR loader and MATCHBOIL.V2 payload with persistence via scheduled tasks
- Campaign attributed to Russia-aligned UAC-0099 group active since mid-2022, previously using WinRAR exploits and phishing
-
Western agencies warn of Russian hacks targeting Zimbra email servers since 2025 — Risky.Biz
Western cyber agencies warn of ongoing Russian hacking campaign targeting Zimbra servers.- Targets: Zimbra email servers used by organizations with sensitive data and compliance needs
- Vulnerability: Stored XSS zero-day (CVE-2025-66376) exploited via CSS @import in webmail client
- Attack method: Malicious code loads Ulej tool to harvest credentials, tokens, 2FA codes, emails
- Attribution: Linked to Russian APT group Laundry Bear (Void Blizzard, TA488) with Ukrainian targeting
- Context: Part of broader Russian espionage on lesser-known email servers since 2022 invasion
🔓 CVEs & KEV
- 18 CVEs reported with the highest severity at 7.3, details not specified in this update.