Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

Read full story on The Hacker News
Share
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
AI disclosure

Summary

A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest. The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.