🚨 ACTIVE EXPLOITATION
- Cl0p Affiliates Exploit PTC Windchill and FlexPLM for Unauthenticated RCE Attacks — thehackernews.com
Cl0p-linked threat actors are exploiting vulnerabilities in PTC Windchill and FlexPLM to achieve unauthenticated remote code execution, targeting manufacturing, automotive, aerospace, and retail sectors.- Targets internet-exposed PTC Windchill and FlexPLM deployments in manufacturing, automotive, aerospace, and retail sectors
- Exploits a pre-authentication information disclosure in FlexPLM WSDL endpoint chained with a server-side flaw in Windchill login servlet
- Enables unauthenticated remote code execution and deployment of JSP web shells under /Windchill/login/
- Suspected exploitation of CVE-2026-12569 (CVSS 9.3) in Windchill and a FlexPLM WSDL endpoint flaw (CVSS 7.5)
- Indicators of compromise include IPs: 216.152.148.54, 216.152.151.204, 104.243.35.63, 5.180.41.35
🕵️ RESEARCH & DEEP DIVES
-
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Payouts — thehackernews.com
DevMan ransomware operators run a centralized portal for payload creation, victim management, and affiliate payouts, targeting sectors including tech, healthcare, finance, and government.- Portal enables payload building, victim chat, finance tracking, team management, and affiliate payouts
- Uses ChaCha20-Poly1305 encryption with multi-threaded file encryption targeting Windows, ESXi, and Linux systems
- Affiliates operate under strict governance with curated victim assignments and an 80-20 revenue split
- Developed a specialized SCADA locker to cause physical damage in industrial control systems
-
CTM360 uncovers real-time account hijacking in insurance phishing campaigns — thehackernews.com
Insurance phishing campaigns now hijack accounts in real time during victim login sessions by relaying credentials and OTPs instantly.- Targets insurance customers using online portals for policies, claims, and payments
- Attackers use Google Ads to lure victims to realistic phishing sites mimicking insurers
- New InsureOTP phishing kit enables session management, live OTP handling, and attacker dashboards
- Campaigns reuse infrastructure across Saudi Arabia, Europe, US, and India