Cl0p Gang’s Latest Tactic Exposes Companies Using PTC Windchill and FlexPLM Software
A new wave of attacks has been spotted targeting organizations using software from PTC (Parametric Technology Corporation) – specifically, those running versions of PTC Windchill and FlexPLM that haven’t implemented the latest security patches. The Cl0p gang, a notorious group known for its ransomware operations, is behind these assaults.
The attack vector involves exploiting an unauthenticated Remote Code Execution (RCE) vulnerability in the software. In simpler terms, hackers can remotely inject malicious code into systems running outdated or vulnerable versions of PTC Windchill and FlexPLM without needing to know any login credentials. This allows them to gain unauthorized access to sensitive data and potentially disrupt business operations.
The Cl0p gang has been leveraging AI-powered tools to identify potential targets. These tools analyze publicly available information, such as company websites and employee profiles, to pinpoint organizations using software with known vulnerabilities. Once identified, the hackers then focus on exploiting these weaknesses before their victims even realize they’re at risk.
PTC Windchill and FlexPLM are widely used in various industries for product development, lifecycle management, and collaboration. The companies affected by this vulnerability include not only manufacturers but also service providers offering digital transformation services to clients with sensitive intellectual property. Given the sophistication of these software applications, it’s no surprise that hackers have set their sights on them.
As AI-driven threat analysis becomes increasingly prevalent, organizations must step up their security measures to stay ahead of these emerging threats. Failing to keep software up-to-date and patch vulnerabilities can prove disastrous, as companies like PTC are discovering firsthand. The practical takeaway here is straightforward: ensure you’re using the latest versions of your software and apply all recommended security patches in a timely manner.
Regularly review your organization’s asset inventory to identify software applications that may be vulnerable to such attacks. Stay informed about newly discovered vulnerabilities and implement robust patch management practices to mitigate potential risks. By doing so, you can significantly reduce the likelihood of falling victim to these types of targeted assaults.
Source: The Hacker News — 2026-07-25