Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11,
Graceful Spider, and Lace Tempest) ransomware campaign are
exploiting flaws in internet-exposed PTC Windmill and FlexPLM
deployments as part of a new data extortion campaign. "Attackers
chain a pre-authentication information disclosure in the FlexPLM
WSDL endpoint with a server-side flaw in the Windchill login
servlet, enabling
Read more https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html

