ctipilot.ch

Cl0p

actor · actor:clop single-source

Financially motivated data-theft extortion group with a multi-year pattern of exploiting a zero-day in a widely deployed enterprise application, exfiltrating at scale, and only then running a mass extortion wave — previously against Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo and Oracle E-Business Suite. Ransom-ISAC, eCrime.ch and DEFUSED attribute the 2026-07 PTC Windchill / FlexPLM extortion campaign to Cl0p affiliate activity; ReliaQuest, quoted by BleepingComputer on 2026-07-24, holds the actor unconfirmed and rests on tradecraft overlap with prior Cl0p campaigns.

Aliases: Clop, Graceful Spider, Chubby Scorpius, FIN11, Lace Tempest

Coverage timeline
11
first 2026-05-04 → last 2026-08-13
Peak priority
high
4 high · 7 notable
Sources cited
52
45 hosts
Sections touched
6
active-threats, trending-vulnerabilities, updates
Co-occurring entities
8
see Related entities below
ATT&CK techniques
14
pinned v19.2 · see below
2026-05-0411 appearances2026-08-13

Hunting pivots

Affected products
PTC WindchillAlibaba fastjsonIBM WebSphere Application ServerLangflowPTC FlexPLMPhoenix Contact CHARX SEC-3000Ruby on Rails Active StorageSiemens Desigo CCAdobe Campaign ClassicArista VeloCloud OrchestratorBalbooa Gridbox for JoomlaCheck Point Security ManagementCisco Secure Firewall Management CenterCitrix NetScaler ADCFortinet FortiOSJetBrains TeamCity

ATT&CK techniques

14 techniques observed across 7 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Resource Development TA0042

T1586.002Compromise Accounts: Email Accounts×1

Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations, such as leveraging them to conduct Phishing for Information, Phishing, or large-scale spam email campaigns. Utilizing an existing persona with a compromised email account may engender a level of trust in a potential victim if they have a relationship with, or knowledge of, the compromised persona. Compromised email accounts can also be used in the acquisition of infrastructure (ex: Domains).

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · ATT&CK page ↗

Initial Access TA0001

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-02/weekly-w31-vuln-status-rollup · ATT&CK page ↗

T1190Exploit Public-Facing Application×5

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-13/clop-leak-site-names-44-victims-swiss-dutch-listings · 2026-08-02/weekly-w31-vuln-status-rollup · 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · 2026-07-14/progress-sharefile-szc-active-exploitation-confirmed · 2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903 · ATT&CK page ↗

Execution TA0002

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903 · ATT&CK page ↗

Persistence TA0003

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-02/weekly-w31-vuln-status-rollup · ATT&CK page ↗

T1136.001Create Account: Local Account×1

Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.

Evidence: 2026-08-02/weekly-w31-vuln-status-rollup · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×3

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-08-13/clop-leak-site-names-44-victims-swiss-dutch-listings · 2026-08-02/weekly-w31-vuln-status-rollup · 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · ATT&CK page ↗

T1542.001Pre-OS Boot: System Firmware×1

Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer.

Evidence: 2026-08-02/weekly-w31-vuln-status-rollup · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×3

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-08-02/weekly-w31-vuln-status-rollup · 2026-07-23/solarwinds-serv-u-2026-3-critical-idor-priv-esc-root · 2026-05-12/ico-fines-south-staffordshire-water-963-900-water-sector-oes · ATT&CK page ↗

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-02/weekly-w31-vuln-status-rollup · ATT&CK page ↗

Stealth TA0005

T1078.001Valid Accounts: Default Accounts×1

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. Default accounts also include default factory/provider set accounts on other types of systems, software, or devices, including the root user account in AWS, the root user account in ESXi, and the default service account in Kubernetes.

Evidence: 2026-08-02/weekly-w31-vuln-status-rollup · ATT&CK page ↗

T1211Exploitation for Stealth×1

Adversaries may exploit vulnerabilities to evade detection by hiding activity, suppressing logging, or operating within trusted or unmonitored components.

Evidence: 2026-08-02/weekly-w31-vuln-status-rollup · ATT&CK page ↗

T1542.001Pre-OS Boot: System Firmware×1

Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmware that operate as the software interface between the operating system and hardware of a computer.

Evidence: 2026-08-02/weekly-w31-vuln-status-rollup · ATT&CK page ↗

Credential Access TA0006

T1606Forge Web Credentials×1

Adversaries may forge credential materials that can be used to gain access to web applications or Internet services. Web applications and services (hosted in cloud SaaS environments or on-premise servers) often use session cookies, tokens, or other materials to authenticate and authorize user access.

Evidence: 2026-08-02/weekly-w31-vuln-status-rollup · ATT&CK page ↗

Discovery TA0007

T1083File and Directory Discovery×1

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · ATT&CK page ↗

Collection TA0009

T1074Data Staged×1

Adversaries may stage collected data in a central location or directory prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location.

Evidence: 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · ATT&CK page ↗

Impact TA0040

T1499.004Endpoint Denial of Service: Application or System Exploitation×1

Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users. Some systems may automatically restart critical applications and services when crashes occur, but they can likely be re-exploited to cause a persistent denial of service (DoS) condition.

Evidence: 2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903 · ATT&CK page ↗

T1657Financial Theft×2

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-08-13/clop-leak-site-names-44-victims-swiss-dutch-listings · 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · ATT&CK page ↗

Story timeline

  1. 2026-08-13UPDATE — Cl0p named 44 victims on its leak site in a single batch, including a Swiss and a Dutch organisation, and one vendor assesses an earlier masked batch as possibly the Windchill campaign
    updatesCl0p's leak site went from masked entries to named European victims in one batch, with no stated intrusion route
  2. 2026-08-092026-W32 looking ahead — items already in motion: a NIS2 law in force in six days, a PAM appliance whose full exploitation detail is due in September, five products that will never be patched, and a federal ISMS deadline five months out
    weekly-looking-aheadW32 outlook — the 15 August Dutch NIS2 clock, WALLIX details due in September, and five products with no fix coming
  3. 2026-08-022026-W31 vulnerability status roll-up — twelve CVEs stood at confirmed exploitation, three carry public exploit chains, and a dense critical tail hit management planes, OT, ERP and the AI toolchain
    weekly-vuln-rollupW31 CVE trajectory — twelve exploited/KEV, three with public chains, and a critical tail with no fix on five
  4. 2026-08-022026-W31 looking ahead — items already in motion: a committed firmware date of 12 August, WebSphere fix packs not due before 3Q2026, an extortion campaign between exfiltration and publication, three flaws with no fix at all, and the CRA reporting clock at six weeks
    weekly-looking-aheadW31 outlook — the 12 August CHARX firmware deadline, WebSphere on interim fixes, and Cl0p's pending listings
  5. 2026-07-27Cl0p-affiliated actors move the PTC Windchill / FlexPLM intrusions (CVE-2026-12569) into a mass extortion-email phase, with no victims named yet
    updatesWindchill exploitation turns to extortion: staff-wide emails name the PLM breach vector, victim listings still pending
  6. 2026-07-23SolarWinds Serv-U 2026.3 — 15 critical IDOR flaws let authenticated users escalate to root RCE on the file-transfer server (CVSS 9.1)
    trending-vulnerabilitiesSolarWinds patches 15 critical IDOR-to-root flaws in the internet-facing Serv-U managed-file-transfer server
  7. 2026-07-14Progress ShareFile Storage Zone Controller — Shadowserver confirms active exploitation of CVE-2026-2699; exposed instances collapse ~30,000 to ~1,000
    updatesHoneypots record in-the-wild exploitation of the ShareFile Storage Zone Controller auth bypass the same day Progress ordered shutdowns
  8. 2026-07-11Progress MOVEit Transfer: pre-auth SFTP DoS (CVE-2026-10699), admin table-scope bypass (CVE-2026-10698) and stored XSS (CVE-2026-11903), patched 2026.0.2
    trending-vulnerabilitiesCERT-FR flags three new MOVEit Transfer CVEs — a pre-auth SFTP memory-leak DoS is reachable on any exposed instance (no exploitation yet)
  9. 2026-05-12ICO fines South Staffordshire Water £963,900 — water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The Record
    active-threatsICO fines South Staffordshire Water £963,900 — water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The
  10. 2026-05-11South Staffordshire Water — ICO £963,900 fine
    weekly-incidents-recap
  11. 2026-05-04Looking ahead — 2026-W19
    weekly-looking-ahead

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

attributed activity

Where this entity is cited

  • weekly-looking-ahead3
  • updates3
  • trending-vulnerabilities2
  • weekly-incidents-recap1
  • active-threats1
  • weekly-vuln-rollup1

Source distribution

  • cve.threatint.eu3 (6%)
  • cert.ssi.gouv.fr2 (4%)
  • cisa.gov2 (4%)
  • ibm.com2 (4%)
  • security-hub.ncsc.admin.ch2 (4%)
  • theregister.com2 (4%)
  • api.ransomware.live1 (2%)
  • arista.com1 (2%)
  • other37 (71%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (52)

Entries about Cl0p (11)

2026-08-13 · view entry permalink →

NOTABLECVE-2026-12569exploitedupdateNATOC3

UPDATE — Cl0p named 44 victims on its leak site in a single batch, including a Swiss and a Dutch organisation, and one vendor assesses an earlier masked batch as possibly the Windchill campaign

UPDATE · originally covered Cl0p-affiliated actors move the PTC Windchill / FlexPLM intrusions (CVE-2026-12569) into a mass extortion-email phase, with no victims named yet (2026-07-27)

the entry on Cl0p's mass-extortion campaign against internet-exposed PTC Windchill and FlexPLM deployments recorded that no victims had yet been listed on the group's leak site. Victims are now being listed, and the shape of the batch — rather than any individual name — is the delta.

Read directly from the Ransomware.live tracker's recent-victims feed this run, 44 named Cl0p listings were all first recorded by the tracker on 2026-08-12 (Ransomware.live, 2026-08-12). The tracker's own record timestamps advance at a near-constant 33 to 40 seconds apart, which is its crawl cadence rather than anything about the leak site — so the feed establishes that these listings were picked up in one sweep, and nothing at all about when Cl0p actually posted them. This entry therefore makes no claim about a publication window. The country codes attached to the records include Switzerland, the Netherlands, Finland, the United Kingdom, Italy, Slovakia, Hungary and France alongside a larger United States contingent; the tracker files the Dutch listing under healthcare and the Swiss one under retail and e-commerce. That tracker mirrors what the leak site publishes and verifies none of it; the company descriptions it prints alongside each record are machine-generated and are not used here. What the feed establishes is that the listings exist, when they appeared, and that European organisations are among them — nothing about whether any of those organisations was in fact compromised.

On whether this batch is the Windchill campaign, the honest answer is that nobody has said so. Foresiet reviewed a batch of 42 masked Cl0p listings and published on 2026-08-10, noting that the advertised data categories recurred with unusual consistency — project repositories, databases, CAD files, engineering drawings, backups and product documentation, with three listings spelling the Windchill product name directly — and that this pattern resembles product-lifecycle-management content more than a general file share. Its conclusion is carefully bounded: it assesses a possible relationship with the broader Cl0p activity involving CVE-2026-12569, while stating that "the available leak-site information alone cannot establish the initial-access vector used against each listed organization", and that it had no forensic access to any affected environment (Foresiet, 2026-08-10). Foresiet's batch is an earlier, masked one; whether the 12 August named batch is the same set unmasked is not stated by any source read this run, and is not asserted here.

What is independently confirmed is the underlying vulnerability's status. CVE-2026-12569, the unauthenticated deserialization remote-code-execution flaw in PTC Windchill PDMLink and FlexPLM, has been in the CISA Known Exploited Vulnerabilities catalog since 2026-06-25 and carries "Known" in its ransomware-campaign-use field, checked directly against catalog version 2026.08.11 (CISA KEV catalog, 2026-08-11). Foresiet also restates the post-exploitation behaviour PTC itself documented: web shells planted under the Windchill login directory, which provide persistent access and command execution after the initial exploitation and which survive patching unless separately found and removed (Foresiet, 2026-08-10).

the available leak-site information alone cannot establish the initial-access vector used against each listed organization

Foresiet 2026-08-10
incident13 Aug 05:12Zsingle-sourceOpen finding ↗

2026-08-09 · view entry permalink →

NOTABLENATOA1

2026-W32 looking ahead — items already in motion: a NIS2 law in force in six days, a PAM appliance whose full exploitation detail is due in September, five products that will never be patched, and a federal ISMS deadline five months out

Items already in motion at the close of ISO week 2026-W32, each with a source and a date. None of these is a prediction.

Dated obligations.

  • 15 August 2026 — the Netherlands' Cyberbeveiligingswet enters into force, together with the companion critical-entities resilience law, imposing registration, duty-of-care, incident-notification and board-accountability duties on more than 8,000 organisations across 18 sectors, with registration in NCSC-NL's national entity register mandatory from that date (Rijksoverheid, 2026-07-07). Relevant to anyone with Dutch entities, suppliers or public-sector counterparts, whose notification behaviour changes on that date.
  • 11 September 2026 — the Cyber Resilience Act's reporting obligations begin, ahead of the regulation's principal obligations in December 2027. 13 September 2026 — ENISA's consultation on the draft EU Managed Security Services certification scheme closes, two days later; providers delivering services under the EU Cybersecurity Reserve would need that certification within two years of the scheme's entry into force, which makes it a procurement gate rather than a voluntary mark. Both were established in prior weekly coverage and neither date has moved.
  • 2 December 2026 — two new prohibited AI practices apply under the AI Act as amended, and 2 December 2027 / 2 August 2028 are the new application dates for high-risk obligations under Annex III and Annex I respectively, following Regulation (EU) 2026/1744 (EUR-Lex, 2026-07-24). Any readiness plan written against 2 August 2026 for Annex III systems is now diarised to the wrong date.
  • 1 January 2027 — Swiss federal administrative units must have built their ISMS. The Informationssicherheitsverordnung requires the administrative units under its Article 2(1)(c) to build their information-security management system within three years of the ordinance's entry into force, and the ordinance entered into force on 1 January 2024 (Fedlex, ISV SR 128.1). Roughly five months remain. The addressee is the federal administration itself; commentary that presents this as a general critical-infrastructure obligation is reading it more broadly than the text supports.

Disclosure and exploitation clocks.

  • September 2026 — full technical details of the WALLIX Bastion authentication bypass are due. WALLIX states that the reporting researchers intend to publish the complete write-up of the CVSS 4.0 base 10.0 flaw that gives an unauthenticated caller full product-administrator control of the appliance — its credential vault and session recordings included — in September (WALLIX, 2026-07-20). Bastion 12.3.7 and 12.4.1 and later are patched, per the CERT-FR advisory that relayed the bulletin (CERT-FR, 2026-08-06). This is a dated window for remediating quietly, not a current threat.
  • Cl0p's Windchill and FlexPLM listings have still not begun. Research re-checked this week found no leak-site listing for that campaign, leaving affected organisations in the interval between exfiltration and publication — the status a prior weekly recorded, unchanged.

Flaws with no fix coming. Five items from this week's coverage will not be resolved by waiting for a vendor, and each therefore converts into an architecture or lifecycle decision:

  • Tobit TeamDavid — 22 CVEs bounded at "Rollout 524" with no fixed release named, against roughly 12,000 internet-facing instances, and researchers reporting that both they and the coordinating national cyber security centre were left without a vendor response (InfoGuard Labs, 2026-08-07).
  • Flowise — three CVEs assigned days after the vendor announced it is winding down; self-hosted operators own the compensating controls.
  • Zbtlink routers (ENDLESSDOORS) — a factory-shipped root backdoor on twenty models, where the discloser's remediation is device replacement.
  • CPDLC over ATN-B1 — five flaws that are properties of the standard, with CISA recording the remediation category as none-available.
  • Check Point's end-of-support management trains — R80 through R81.10 are listed as affected by this week's unauthenticated management-authentication bypass with no fix on offer.

In development, no date. NCSC UK confirms it is working with international partners on a reference architecture for forensic observability in network appliances, intended to give vendors something concrete to build to (NCSC UK, 2026-07-29). It is not published, and no publication date is stated. Separately, the Metabase SQL-injection zero-day exploited this week still has no CVE identifier assigned, so it will not reach any process that waits for one.

Builds on: 2026-08-09/wallix-bastion-rest-api-unauth-admin-cvss10 · 2026-08-09/teamdavid-tobit-22-cves-unauth-mailbox-takeover-dach · 2026-08-08/flowise-three-cves-vendor-sunset-no-fix-coming · 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor · 2026-08-08/cpdlc-atn-b1-five-protocol-flaws-no-mitigation-available · 2026-08-05/check-point-cve-2026-18574-management-auth-bypass · 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally

outlook09 Aug 23:45Zmulti-sourceOpen finding ↗

2026-08-02 · view entry permalink →

NOTABLEexploitedNATOB2

2026-W31 looking ahead — items already in motion: a committed firmware date of 12 August, WebSphere fix packs not due before 3Q2026, an extortion campaign between exfiltration and publication, three flaws with no fix at all, and the CRA reporting clock at six weeks

Items already in motion at the close of 2026-W31, each with a source and a date. None of these is a prediction.

A firmware release with a committed deadline — 12 August. CERT@VDE's advisory covering 20 vulnerabilities in Phoenix Contact CHARX SEC-3xxx EV charging controllers, five of them CVSS 9.8 with an unauthenticated network vector, published without the fix: "the updated firmware will be made available as soon as possible, but no later than August 12, 2026." (CERT@VDE, 2026-07-30). Until then the vendor's only offered control is closed-network operation behind a firewall — and one of the flaws makes the on-device firewall unavailable for a window during every shutdown. The date is checkable and worth checking.

Permanent WebSphere fix packs not expected before 3Q2026. IBM has no workaround for the CVSS 9.8 missing-authentication flaw in the WebSphere Application Server traditional administrative console, and targets the permanent Fix Packs 9.0.5.29 and 8.5.5.31 for 3Q2026, leaving the interim fix under APAR DT496500 as the only remediation now (IBM PSIRT, 2026-07-28); a companion bulletin the same day carries the deserialization flaw and APAR PH72166 (IBM PSIRT, 2026-07-28). Estates that defer interim fixes on principle are deferring past a quarter boundary.

An extortion campaign between exfiltration and publication. Cl0p-affiliated actors have been sending staff-wide emails naming PTC Windchill as the breach vector, but as of the last reported observation the second shoe had not dropped: "as of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign." (Ransom-ISAC, 2026-07-22). Any organisation that ran an internet-exposed, unpatched Windchill or FlexPLM instance in June sits inside that gap, and the campaign's own precedent is that listings follow.

Three flaws with no fix, and one of them exploited. Langflow's pre-authentication eval injection is being exploited with no documented fixed version, and ZDI's only stated mitigation is to restrict interaction with the product (Zero Day Initiative, 2026-01-09). fastjson 1.x will not receive one: "FastJson 1.x is no longer actively maintained, and no patched 1.x version has been released for this vulnerability." (Imperva, 2026-07-24). And Siemens records the entire Desigo CC V7 family under remediation category none_available, with network segmentation as the only offered control (Siemens ProductCERT, 2026-07-14). These three leave the vulnerability queue by being made unreachable or not at all.

An embargo that has already broken. The Rails security team abandoned its plan to withhold the CVE-2026-66066 Active Storage exploitation details until 2026-08-28, publishing the attack write-up four weeks early along with a forensic-evidence guide and tooling to determine whether an application was vulnerable and whether it was exploited (Ruby on Rails security team, 2026-07-31). The window in which the chain was private is closed; what remains in motion is the population of unpatched applications, and the published forensic check is how an operator establishes which side of it they are on.

The CRA reporting clock, at six weeks. "Although the principal obligations will apply from December 11, 2027, reporting obligations take effect on September 11, 2026." (Hunton Andrews Kurth, 2026-07-29). From that date the regulation's reporting obligations bind manufacturers of products with digital elements — which for this constituency is a change in what EU-market suppliers owe their customers, arriving more than a year before the rest of the regulation applies. The notification window and article number are deliberately not stated here: no source fetched this run carries them.

The updated firmware will be made available as soon as possible, but no later than August 12, 2026.

CERT@VDE 2026-07-30

As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign.

Ransom-ISAC / eCrime.ch / DEFUSED 2026-07-22

Although the principal obligations will apply from December 11, 2027, reporting obligations take effect on September 11, 2026.

Hunton Andrews Kurth 2026-07-29

Builds on: 2026-08-02/phoenix-contact-charx-sec-3xxx-unauth-root-no-firmware-yet · 2026-08-01/ibm-websphere-cve-2026-14512-14446-preauth-no-fix-pack · 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · 2026-07-29/cve-2026-0769-langflow-preauth-eval-rce-exploited-not-in-kev · 2026-07-27/cve-2026-16723-fastjson-1x-spring-boot-fat-jar-rce-no-patch · 2026-07-29/cve-2025-15467-siemens-desigo-cc-cms-overflow-v7-unfixed · 2026-08-02/cve-2026-66066-rails-attack-chain-public-forensic-tooling

outlook02 Aug 23:59Zmulti-sourceOpen finding ↗

Earlier coverage (8)

2026-08-02HIGHexploitedNATOB22026-W31 vulnerability status roll-up — twelve CVEs stood at confirmed exploitation, three carry public exploit chains, and a dense critical tail hit management planes, OT, ERP and the AI toolchainConsolidated status of the CVEs this pipeline covered operationally in ISO week 2026-W31, each with its trajectory this week set against when it was first covered. Newly exploited or newly KEV-listed this week: CVE-2026-16812 (Arista VeloCloud Orchestrator, CVSS 10.0, KEV the day of disclosure), CVE-2025-68686 (FortiOS SSL-VPN patch bypass), CVE-2026-20316 (Cisco Secure FMC static credential), CVE-2026-16723 (fastjson 1.x, no patch exists) and CVE-2026-65884 / CVE-2026-65885 (Balbooa Gridbox, 92 planted admin accounts observed). Already-exploited items that moved: CVE-2026-16232 gained a published root cause, CVE-2026-12569 entered a mass extortion-email phase, CVE-2026-42897 gained a state attribution, CVE-2013-4786 gained evidence of in-the-wild abuse, and CVE-2026-39987 was corrected upward to confirmed command execution on 11 endpoints. Full per-CVE detail lives in the referenced operational entries; this roll-up carries only the week's trajectory.2026-07-27HIGHexploitedupdateNATOB2Cl0p-affiliated actors move the PTC Windchill / FlexPLM intrusions (CVE-2026-12569) into a mass extortion-email phase, with no victims named yetThe PTC Windchill / FlexPLM pre-auth deserialization RCE (CVE-2026-12569) that CISA KEV-listed in June has entered an extortion phase attributed to Cl0p affiliates: from 20 July, Ransom-ISAC observed emails subject-lined "Windchill PDMLink module serious data leak" sent from compromised accounts to hundreds of staff per victim organisation, naming Windchill as the breach vector. As of 22 July no victims had been listed on Cl0p's leak site, so organisations that ran an internet-exposed, unpatched instance in June are in the window between exfiltration and publication.2026-07-23NOTABLENATOA1SolarWinds Serv-U 2026.3 — 15 critical IDOR flaws let authenticated users escalate to root RCE on the file-transfer server (CVSS 9.1)SolarWinds Serv-U 15.5.4 HF1 and earlier carry 16 CVEs — 15 rated critical (CVSS 9.1) — that are insecure-direct-object-reference and broken-access-control flaws in the managed-file-transfer web console. An authenticated user, in several cases needing only group- or domain-administrator scope, can escalate to system administrator and reach remote code execution as root on the underlying host (reduced impact on Windows). All were reported through SolarWinds' bug-bounty program and fixed in Serv-U 2026.3 (2026-07-21); no in-the-wild exploitation is confirmed, but Serv-U is an internet-facing MFT server of exactly the class ransomware affiliates have targeted post-disclosure.2026-07-14HIGHexploitedupdateNATOB1Progress ShareFile Storage Zone Controller — Shadowserver confirms active exploitation of CVE-2026-2699; exposed instances collapse ~30,000 to ~1,000Update to the 2026-07-13 ShareFile shutdown entry. Shadowserver Foundation honeypots first recorded active, in-the-wild exploitation attempts against the ShareFile Storage Zone Controller pre-auth authentication bypass CVE-2026-2699 on Friday 2026-07-10 — the same day Progress issued its emergency power-off order — and the internet-exposed instance count fell from watchTowr's April tally of ~30,000 to roughly 1,000 by 2026-07-13. A Recorded Future analyst publicly assessed possible Clop involvement; Progress has named no actor and disclosed no root cause. On-prem operators still running Storage Zone Controllers should keep them off.2026-07-11NOTABLENATOA2Progress MOVEit Transfer: pre-auth SFTP DoS (CVE-2026-10699), admin table-scope bypass (CVE-2026-10698) and stored XSS (CVE-2026-11903), patched 2026.0.2France's CERT-FR/ANSSI advisory CERTFR-2026-AVI-0856 (2026-07-10) covers three newly-patched flaws in Progress MOVEit Transfer, the managed file-transfer product with a history of mass exploitation (Cl0p, 2023): CVE-2026-10699 (CVSS 7.5) is an unauthenticated SFTP-service memory leak an attacker can drive to denial of service; CVE-2026-10698 (CVSS 7.2) lets an admin-level user bypass Custom Reports table-scope restrictions to read or manipulate data outside scope; CVE-2026-11903 (CVSS 8.0) is a low-privilege stored XSS in the Ad Hoc module. No exploitation or public PoC is reported. Fixed in 2026.0.2 (and the 2025.0.8 / 2025.1.4 branch releases); Swiss/EU public-sector and finance operators running internet-facing MOVEit should prioritise the upgrade given the product's exposure profile and exploitation history.2026-05-12HIGHICO fines South Staffordshire Water £963,900 — water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The RecordICO fines South Staffordshire Water £963,900 for the 2020–2022 Cl0p intrusion. Regulator-side findings call out inadequate vulnerability management, unpatched critical systems, obsolete unsupported software (Windows Server 2003) and partial SIEM coverage; 633,887 individuals' data was published on the dark web from a total holding of about 1.85 million customer records (ICO notice, 2026-05-11). Reporting by The Record adds the ZeroLogon / two-DC kill-chain detail2026-05-11NOTABLESouth Staffordshire Water — ICO £963,900 fineICO fines South Staffordshire Water £963,900 over the 2022 Cl0p ZeroLogon kill-chain intrusion (daily 2026-05-12). The water-sector OES finding with the partial SIEM coverage detail (5% host-inventory coverage) is the operational lesson for any utility / critical-infrastructure operator with patchy telemetry.2026-05-04NOTABLELooking ahead — 2026-W19Canvas / Instructure extortion deadline — Tuesday 2026-05-12 (two days out). Second-intrusion claim against Instructure made 2026-05-08 despite the May 8 patches; seven Dutch universities disconnected; Dutch DPA and ICO engaged.