ReliaQuest has documented a custom JSP web shell deployed by Clop after exploitation of CVE-2026-12569 on PTC Windchill and FlexPLM servers. The implant maps design vaults, decrypts keystore credentia

ReliaQuest has documented a custom JSP web shell deployed by Clop after exploitation of CVE-2026-12569 on PTC Windchill and FlexPLM servers. The implant maps design vaults, decrypts keystore credentials, and queries databases via the application's own identity.

3 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

ReliaQuest has documented a custom JSP web shell deployed by Clop after exploitation of CVE-2026-12569 on PTC Windchill and FlexPLM servers. The implant maps design vaults, decrypts keystore credentia

mastodon:infosec-exchangeother41d ago kagi ↗

ReliaQuest has documented a custom JSP web shell deployed by Clop after exploitation of CVE-2026-12569 on PTC Windchill and FlexPLM servers. The implant maps design vaults, decrypts keystore credentials, and queries databases via the application's own identity. # Clop # PTCWindchill # WebShell # ThreatIntelligence https:// cyberworldops.eu/en/clop-explo its-windchill-jsp-web-shell-steals-credentia

ReliaQuest found Clop deploying a purpose-built JSP web shell that abuses Windchill's internal APIs to decrypt secrets and steal files after exploiting CVE-2026-12569. # Clop # Windchill # CVE20261256

mastodon:infosec-exchangeother40d ago kagi ↗

ReliaQuest found Clop deploying a purpose-built JSP web shell that abuses Windchill's internal APIs to decrypt secrets and steal files after exploiting CVE-2026-12569. # Clop # Windchill # CVE202612569 # WebShell # DataExfiltration https:// meterpreter.org/clop-windchill -webshell-cve-2026-12569/?utm_source=mastodon&utm_medium=jetpack_social

⚠️ CRITICAL: Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data Clop ransomware operators deployed a custom JSP web shell targeting PTC Windchill and FlexPLM servers, explo

mastodon:infosec-exchangeother40d ago kagi ↗

⚠️ CRITICAL: Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data Clop ransomware operators deployed a custom JSP web shell targeting PTC Windchill and FlexPLM servers, exploiting CVE-2026-12569 to decrypt stored credentials and exfiltrate engineering data. Any organization running vulnerable Windchill instances is at immediate risk of credential compromise, late… https:/