π¨ ACTIVE EXPLOITATION
- Clop Exploits Critical PTC Windchill and FlexPLM Flaw for Data Theft
CVE-2026-12569
Clop is exploiting a critical Windchill and FlexPLM flaw to steal data.- PTC Windchill PDMLink and FlexPLM customers across manufacturing, aerospace, defense, automotive, energy and retail are targeted.
- CVE-2026-12569 is an unsafe-deserialization flaw enabling unauthenticated remote code execution; releases before 11.0 M030 are affected.
- Attackers chain FlexPLM WSDL information disclosure with a crafted payload against the Windchill login servlet.
- Clop deploys a custom JSP web shell to decrypt credentials, map file vaults and exfiltrate product data.
- Observed indicators include the X-windchill-req header, flst.txt, hex-named JSP files under /Windchill/login/, and C2 IP 79.141.160.78.
π Source: ptc.com Β· π Coverage: reliaquest.com Β· π via Cyber Security News
π΅οΈ RESEARCH & DEEP DIVES
- Slovakia finds Russian components and security risks in speed cameras
Slovakia found Russian components in traffic speed cameras intended for its road-enforcement system.- Slovakiaβs Interior Ministry and traffic-enforcement project are affected.
- Two tested radar cameras contained Russian components and could pose a state-security risk.
- The cameras were supplied by Soitron, which said it was misled about their origin.
- The equipment was reportedly made by St. Petersburg-based Simicon and sold through intermediaries, including a Cyprus company.
- Opposition claims the cameras use Russian software and could monitor traffic, people and goods.
π Source: dennikn.sk Β· π Coverage: howweceeit.substack.com Β· π via Risky Business News
π CVEs & KEV
- CVE-2026-70408 β CVSS 8.7 β An incorrect authorization vulnerability exists in acmailer, which may allow ...