Multiple ransomware-as-a-service groups including Booba Project, qilin, rhysida, Spirals, and incransom posted new victim claims to their leak sites between 2026-09-23 and 2026-09-25, announcing compromised organizations across US counties and sectors.
Between September 19 and 21, the ShinyHunters extortion group infiltrated the Clop ransomware operation's data leak site, defacing it and allegedly stealing server data, source code, and Tor private keys. The defacement was confirmed; the broader theft claims remain unverified.
🔴 Hogan Lovells Cadwalader — listed by Silentransomgroup 📍 Professional Services · 21 Sep 2026 🏴 Silentransomgroup has listed 145 victims since June 2022. #ransomware #silentransomgroup #threatintel Professional Services sector.
Security researchers and vendors disclosed numerous critical vulnerabilities including zero-day flaws in SonicWall SMA1000 devices, infrastructure flaws tracked in an InfraTrust report, and large-scale malware campaigns using GitHub repositories and DDoS botnets. The Dysphoria botnet has infected approximately 200,000 devices worldwide.
Between August 18–20, 2026, security researchers linked a custom Java web shell to the Clop ransomware gang, designed specifically to exploit PTC Windchill and FlexPLM enterprise software servers. The tool included features to decrypt stored credentials and facilitate data theft.
Hacking group ShinyHunters compromised and defaced the data leak site of the Clop ransomware gang on September 25 via an unpatched Grav CMS path traversal vulnerability. Clop relocated to a new Tor address after confirming the breach.
ReliaQuest has documented a custom JSP web shell deployed by Clop after exploitation of CVE-2026-12569 on PTC Windchill and FlexPLM servers. The implant maps design vaults, decrypts keystore credentials, and queries databases via the application's own identity.
The Clop ransomware gang is conducting a data theft extortion campaign targeting internet-exposed instances of PTC Windchill and FlexPLM product lifecycle management systems. The attackers are attempting to steal data and extort affected organizations.
com/blog/clop-re... com Clop's exploitation of CVE-2026-12569 in PTC Windchill returns the group to mass exploitation with a custom web shell built for full data theft.
The cybercriminal group Cl0p has exploited vulnerability CVE-2026-12569 in PTC Windchill and FlexPLM manufacturing software. Security researchers at Ransomware-ISAC have documented and published details of the exploitation.
On September 21, 2026, rival hacking group ShinyHunters compromised Clop's leak site and demanded eight figures in ransom. ShinyHunters threatened to expose companies that had paid Clop to suppress leaked data.