CTIPilot

Cl0p

actor · actor:clop

Financially motivated data-theft extortion group with a multi-year pattern of exploiting a zero-day in a widely deployed enterprise application, exfiltrating at scale, and only then running a mass extortion wave, previously against Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo and Oracle E-Business Suite. Ransom-ISAC, eCrime.ch and DEFUSED attribute the 2026-07 PTC Windchill / FlexPLM extortion campaign to Cl0p affiliate activity; ReliaQuest, quoted by BleepingComputer on 2026-07-24, holds the actor unconfirmed and rests on tradecraft overlap with prior Cl0p campaigns.

Aliases: Clop, Graceful Spider, Chubby Scorpius, FIN11, Lace Tempest

Coverage timeline
5
first 2026-05-12 → last 2026-07-23
Peak priority
critical
1 critical · 2 high · 2 notable
Sources cited
36
24 hosts
Sections touched
3
active-threats, deep-dive, trending-vulnerabilities
Co-occurring entities
8
see Co-occurring entities below
ATT&CK techniques
16
pinned v19.2 · see below
2026-05-125 appearances2026-07-23

ATT&CK techniques

16 techniques observed across 5 entries, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Resource Development TA0042

T1586.002Compromise Accounts: Email Accounts×1

Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations, such as leveraging them to conduct Phishing for Information, Phishing, or large-scale spam email campaigns. Utilizing an existing persona with a compromised email account may engender a level of trust in a potential victim if they have a relationship with, or knowledge of, the compromised persona. Compromised email accounts can also be used in the acquisition of infrastructure (ex: Domains).

Evidence: 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

Initial Access TA0001

T1190Exploit Public-Facing Application×3

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-07-13/progress-sharefile-storage-zone-controller-shutdown · 2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903 · 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

Execution TA0002

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903 · ATT&CK page ↗

Persistence TA0003

T1505Server Software Component×1

Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application. Adversaries may install malicious components to extend and abuse server applications.

Evidence: 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×2

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-07-13/progress-sharefile-storage-zone-controller-shutdown · 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

Privilege Escalation TA0004

T1068Exploitation for Privilege Escalation×2

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Evidence: 2026-07-23/solarwinds-serv-u-2026-3-critical-idor-priv-esc-root · 2026-05-12/ico-fines-south-staffordshire-water-963-900-water-sector-oes · ATT&CK page ↗

Stealth TA0005

T1620Reflective Code Loading×1

Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules).

Evidence: 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

Credential Access TA0006

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

T1555Credentials from Password Stores×1

Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.

Evidence: 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

Discovery TA0007

T1083File and Directory Discovery×1

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

Collection TA0009

T1074Data Staged×1

Adversaries may stage collected data in a central location or directory prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected Data. Interactive command shells may be used, and common functionality within cmd and bash may be used to copy data into a staging location.

Evidence: 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

Exfiltration TA0010

T1041Exfiltration Over C2 Channel×1

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

Evidence: 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

Impact TA0040

T1499.004Endpoint Denial of Service: Application or System Exploitation×1

Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users. Some systems may automatically restart critical applications and services when crashes occur, but they can likely be re-exploited to cause a persistent denial of service (DoS) condition.

Evidence: 2026-07-11/moveit-transfer-certfr-cve-2026-10699-10698-11903 · ATT&CK page ↗

T1657Financial Theft×1

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

Evidence: 2026-06-20/ptc-windchill-cve-2026-12569-unauthenticated-java-deserializ · ATT&CK page ↗

Story timeline

  1. 2026-07-23SolarWinds Serv-U 2026.3, 15 critical IDOR flaws let authenticated users escalate to root RCE on the file-transfer server (CVSS 9.1)
    trending-vulnerabilitiesSolarWinds patches 15 critical IDOR-to-root flaws in the internet-facing Serv-U managed-file-transfer server
  2. 2026-07-13Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat', day three, no patch or root cause disclosed
    active-threatsProgress tells all on-prem ShareFile Storage Zone Controller customers to power off their servers over an undisclosed 'credible external security threat'
  3. 2026-07-11Progress MOVEit Transfer: pre-auth SFTP DoS (CVE-2026-10699), admin table-scope bypass (CVE-2026-10698) and stored XSS (CVE-2026-11903), patched 2026.0.2
    trending-vulnerabilitiesCERT-FR flags three new MOVEit Transfer CVEs; a pre-auth SFTP memory-leak DoS is reachable on any exposed instance (no exploitation yet)
  4. 2026-06-20PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane
    deep-dive
  5. 2026-05-12ICO fines South Staffordshire Water £963,900, water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The Record
    active-threatsICO fines South Staffordshire Water £963,900, water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The

Relationships explore in graph

Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.

attributed activity

Where this entity is cited

  • active-threats2
  • trending-vulnerabilities2
  • deep-dive1

Source distribution

  • bleepingcomputer.com5 (14%)
  • attack.mitre.org3 (8%)
  • cve.threatint.eu3 (8%)
  • heise.de3 (8%)
  • security-hub.ncsc.admin.ch2 (6%)
  • theregister.com2 (6%)
  • api.ransomware.live1 (3%)
  • bankinfosecurity.com1 (3%)
  • other16 (44%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (36)

Entries about Cl0p (5)

2026-06-20 · view entry permalink →

CRITICALCVE-2026-12569exploitedupdated

PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane

Context. PTC Windchill and the FlexPLM apparel/retail variant are dominant product-lifecycle-management platforms across DACH manufacturing, aerospace, automotive and the defence-industrial base, systems that hold the engineering crown jewels (CAD, BOMs, supplier data) and increasingly sit behind internet-reachable web front-ends to support distributed engineering and supplier portals. That combination (high-value data and a network-exposed login surface) is what makes CVE-2026-12569 an emergency rather than a routine critical.

The flaw. CVE-2026-12569 (CVSS 3.1 10.0; CVSS 4.0 9.3) is an unsafe deserialization of untrusted data reachable on the web-based Windchill/FlexPLM login interface before authentication (NCSC-CH, 2026-06-19). A deserialization sink consumes attacker-controlled serialized data at the network edge; the only prerequisite is network access to the login endpoint, with no valid credentials, no prior foothold and no user interaction. PTC released fixes on 2026-06-15 and auto-patched cloud-hosted tenants (PTC PSIRT). Affected on-premises builds span the 11.x, 12.0.x, 12.1.x, 13.0.x and 13.1.0.0–13.1.3.0 lines as well as releases prior to 11.0 M030, verify exact fixed-build numbers against the PTC advisory for your release train.

Exploitation status. Both BSI (Germany) and NCSC-CH treat this as actively exploited: Heise reported active exploitation deploying backdoors on vulnerable systems, and the BSI escalated to direct after-hours phone calls to known Windchill operators, a step reserved for the highest-urgency advisories (Heise Security, 2026-06-19).

Kill chain (mapped to MITRE ATT&CK).

  • Initial access / execution: pre-auth deserialization RCE against the public-facing login interface (T1190 Exploit Public-Facing Application). The deserialization gadget executes in the context of the Windchill Java application server.
  • Persistence: the sources report follow-on backdoor deployment on compromised hosts; this is consistent with installing a server-side implant or web component on the application server (T1505.003 Server Software Component: Web Shell), though the specific implant class was not detailed publicly.
  • Discovery / collection: a foothold on a PLM server places the attacker adjacent to engineering IP, supplier records and integration credentials to ERP/CAD systems.

Hunt and detection concepts (no IOCs). Watch Windchill application-server logs for Java deserialization exception bursts and class-resolution errors around the login path; alert on unexpected child processes spawned by the Windchill application-server process (JBoss/WildFly/WebLogic parent), which should not normally fork shells or scripting interpreters; flag anomalous inbound connections to Windchill HTTP/HTTPS ports from CIDR ranges that never legitimately reach the login surface; and treat any new outbound connections initiated by a PLM server as suspect, since these servers should have tightly-bounded egress.

Hardening / mitigation. Apply the 2026-06-15 patch on every on-premises instance and confirm cloud tenants were auto-patched. Until patched, remove the login interface from direct internet exposure, front it with VPN or an authenticating reverse proxy and segment the PLM tier so it cannot be reached from untrusted networks. Constrain the application-server service account to least privilege and restrict its outbound network paths so a successful deserialization yields the smallest possible blast radius.

Active exploitation is underway to deploy backdoors on vulnerable systems.

Heise Security

Current exploitation status: Actively Exploited

NCSC-CH Security Hub

UPDATE (originally covered 2026-06-20): CISA added the PTC Windchill PDMLink / FlexPLM pre-auth deserialization RCE (CVE-2026-12569) to its Known Exploited Vulnerabilities catalog on 2026-06-25, confirming active in-the-wild exploitation, the operational shift from the disclosure we deep-dived on …

ctipilot v2 brief (migrated)

On 20 July, Ransom-ISAC began observing an alleged Cl0p ransomware (aka Graceful Spider, Chubby Scorpius, FIN11, Lace Tempest) data extortion campaign sending emails with a subject line, “Windchill PDMLink module serious data leak” to an unknown number of affected organizations

As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign.

Ransom-ISAC / eCrime.ch / DEFUSED 2026-07-22

The actor behind these attacks remains unconfirmed. however, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories.

BleepingComputer, quoting ReliaQuest

the available leak-site information alone cannot establish the initial-access vector used against each listed organization

Foresiet 2026-08-10

"We are aware of a potential incident. We are working with our security teams and relevant experts to investigate," a Shell spokesperson told BleepingComputer when asked to confirm Clop's data theft claims.

BleepingComputer 2026-07-24

Philips describes the incident as “an attempted cyberattack on a specific company server containing internal data.” The healthcare technology company says the incident has since been brought under control. “This has no impact on customer environments,” a spokesperson added.

NL Times 2026-08-13

Clop's Windchill and FlexPLM attacks were also confirmed by the Ransomware Information Sharing and Analysis Centre (Ransom-ISAC), a non-profit organization dedicated to the tracking and defense against ransomware threats, and by cybersecurity company ReliaQuest, which said that the threat actors have been deploying JSP webshells that allow them to steal sensitive data from victims' compromised PLM platforms.

BleepingComputer 2026-07-24

A single "S" command to the web shell returns Windchill's directory-management and administrative credentials in plaintext.

It accepts a Base64-encoded ZIP file containing compiled Java bytecode, loads it directly into memory, and executes it.

Identifying this activity requires header logging that captures non-standard values, response decompression, and TLS inspection; without all three, coverage against this web shell's traffic is partial at best.

This activity was highly likely conducted by the Clop extortion group.

ReliaQuest Threat Research Team 2026-08-18

While a GE spokesperson said the company is aware of the claim and is "working to assess the potential issue," a Philips spokesperson confirmed its systems were breached but said the incident has been contained and didn't affect customers.

BleepingComputer 2026-07-24
Updaterun 2026-06-27-40e791d4actionscvesevidenceregionssourcestagsbody

CISA added the PTC Windchill PDMLink / FlexPLM pre-auth deserialization RCE (CVE-2026-12569) to its Known Exploited Vulnerabilities catalog on 2026-06-25, confirming active in-the-wild exploitation, the operational shift from the disclosure we deep-dived on June 20 (The Hacker News, 2026-06-26).

Reported post-exploitation deploys JSP web shells to /Windchill/login/<16-hex>.jsp plus a flst.txt persistence marker, concrete hunt artefacts beyond the earlier abstract RCE description. ENISA's EUVD entry corroborates the unauthenticated deserialization root cause (ENISA EUVD EUVD-2026-37831). The driver for Swiss/EU manufacturing, pharma and aerospace operators running Windchill is the confirmed exploitation and the web-shell pattern, not the US-only federal remediation date; patch per PTC CS473270 and hunt web-server logs for .jsp creation under /Windchill/login/.

Updaterun 2026-07-27T0409Z-intelactionsaffected_productscvesentitiesevidencesectorssourcestagstechniquesbody

The PTC Windchill / FlexPLM deserialization RCE this pipeline covered when CISA confirmed exploitation has moved from quiet data theft into open extortion. From 20 July a joint advisory by Ransom-ISAC, eCrime.ch and DEFUSED records that it "began observing an alleged Cl0p ransomware (aka Graceful Spider, Chubby Scorpius, FIN11, Lace Tempest) data extortion campaign sending emails with a subject line, “Windchill PDMLink module serious data leak” to an unknown number of affected organizations" (Ransom-ISAC / eCrime.ch / DEFUSED, 2026-07-22). The delivery pattern is the operationally useful part: the messages are sent from randomly compromised accounts and go to hundreds of recipients inside the victim organisation at once, carrying the attacker's current contact addresses; an approach the same advisory notes is consistent with the Oracle E-Business Suite campaign of last year apart from the new addresses (same advisory).

Two facts bound the response window. First, no victim has been named: "As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign" (same advisory), so an affected organisation's first and possibly only warning is the staff-wide email, not a leak-site entry. Second, attribution is unsettled and the two reporting streams disagree in a way worth carrying: the joint advisory treats this as Cl0p affiliate activity, while ReliaQuest, quoted by BleepingComputer, states that "The actor behind these attacks remains unconfirmed. however, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories" (BleepingComputer, 2026-07-24). The underlying access route is unchanged from the June coverage, a pre-authentication information disclosure in the FlexPLM WSDL endpoint chained with the Windchill login-servlet flaw, followed by JSP web shells and staged data theft (Ransom-ISAC / eCrime.ch / DEFUSED, 2026-07-22).

One correction to how this pipeline previously framed remediation, because it changes who is still exposed: there is no version floor above which an installation is safe. PTC ships a patch per version, and its own change log records the older Windchill lines being patched between 18 and 19 June (13.0.2 on 18 June, and 11.0 M030 alongside 13.1.1 on 19 June) while the SUPs for 13.1.2 and 13.1.3, and the first release naming FlexPLM as well as Windchill, only arrived on 14 July 2026 (PTC, 2026-07-14). 11.0 M030 appears in that patch list as a version that receives a fix, not as a boundary below which systems are safe, and there is no lower bound at all: NVD states the flaw "also impacts Windchill and FlexPLM releases prior to 11.0 M030", and above that it enumerates discrete affected releases rather than a continuous range, topping out at Windchill 13.1.3 and FlexPLM 13.0.3. The practical consequence is narrower than a version number suggests but sharper for those it catches: an estate on 13.1.2 or 13.1.3 had no patch available between CISA's KEV confirmation on 25 June and the SUP release on 14 July, whereas a 13.1.1 estate could have patched from 19 June. Neither a high version number nor a version above 11.0 M030 is therefore evidence of remediation, and only the per-version list in PTC's eSupport article CS473270 answers the question.

Triage: the extortion email is itself a detectable event with a clean discriminator. A legitimate internal security notice originates from a known internal sender and the organisation's own mail infrastructure; this pattern is a large recipient set inside one organisation receiving mail from a compromised account with no prior relationship to it, referencing a specific internal application by name. Mail-flow telemetry showing that fan-out to a wide internal distribution list from a previously-unseen sender (rather than the message content) is the signal, and it should route to incident response rather than to the phishing-report queue.

Updaterun 2026-08-13T0412Z-intelcvesevidencesectorssourcesbody

The entry on Cl0p's mass-extortion campaign against internet-exposed PTC Windchill and FlexPLM deployments recorded that no victims had yet been listed on the group's leak site. Victims are now being listed, and the shape of the batch (rather than any individual name) is the delta.

Read directly from the Ransomware.live tracker's recent-victims feed this run, 44 named Cl0p listings were all first recorded by the tracker on 2026-08-12 (Ransomware.live, 2026-08-12). The tracker's own record timestamps advance at a near-constant 33 to 40 seconds apart, which is its crawl cadence rather than anything about the leak site, so the feed establishes that these listings were picked up in one sweep, and nothing at all about when Cl0p actually posted them. This entry therefore makes no claim about a publication window. The country codes attached to the records include Switzerland, the Netherlands, Finland, the United Kingdom, Italy, Slovakia, Hungary and France alongside a larger United States contingent; the tracker files the Dutch listing under healthcare and the Swiss one under retail and e-commerce. That tracker mirrors what the leak site publishes and verifies none of it; the company descriptions it prints alongside each record are machine-generated and are not used here. What the feed establishes is that the listings exist, when they appeared, and that European organisations are among them, nothing about whether any of those organisations was in fact compromised.

On whether this batch is the Windchill campaign, the honest answer is that nobody has said so. Foresiet reviewed a batch of 42 masked Cl0p listings and published on 2026-08-10, noting that the advertised data categories recurred with unusual consistency (project repositories, databases, CAD files, engineering drawings, backups and product documentation, with three listings spelling the Windchill product name directly) and that this pattern resembles product-lifecycle-management content more than a general file share. Its conclusion is carefully bounded: it assesses a possible relationship with the broader Cl0p activity involving CVE-2026-12569, while stating that "the available leak-site information alone cannot establish the initial-access vector used against each listed organization", and that it had no forensic access to any affected environment (Foresiet, 2026-08-10). Foresiet's batch is an earlier, masked one; whether the 12 August named batch is the same set unmasked is not stated by any source read this run, and is not asserted here.

What is independently confirmed is the underlying vulnerability's status. CVE-2026-12569, the unauthenticated deserialization remote-code-execution flaw in PTC Windchill PDMLink and FlexPLM, has been in the CISA Known Exploited Vulnerabilities catalog since 2026-06-25 and carries "Known" in its ransomware-campaign-use field, checked directly against catalog version 2026.08.11 (CISA KEV catalog, 2026-08-11). Foresiet also restates the post-exploitation behaviour PTC itself documented: web shells planted under the Windchill login directory, which provide persistent access and command execution after the initial exploitation and which survive patching unless separately found and removed (Foresiet, 2026-08-10).

Updaterun 2026-08-15T0412Z-intelcvesevidenceregionssectorssourcesbody

Yesterday's entry recorded that no organisation named in Cl0p's batch had confirmed a compromise and that leak-site information alone could not establish an access route for any listed victim. Two of them have now spoken, and a second security vendor has published the first post-exploitation detail for the campaign.

Philips, the Netherlands-headquartered health-technology group, describes the incident as an attempted cyberattack on a specific company server containing internal data, says it has since been brought under control, and states it has no impact on customer environments (NL Times, 2026-08-13). Shell told BleepingComputer it is aware of a potential incident and is working with its security teams and relevant experts to investigate (BleepingComputer, 2026-08-14). Neither statement confirms the volumes Cl0p advertises: the group claims 89 GB from Shell and 13.5 GB from Philips, figures that reach the reporting through a leak-site monitoring platform which cautions they come directly from the attackers and are not independently verified (NL Times, 2026-08-13). BleepingComputer counts Shell among 43 new victims Cl0p listed, likely targeted through internet-exposed PTC Windchill and FlexPLM instances via CVE-2026-12569, and reports General Electric named in the same batch with no comment yet from GE, Philips or PTC to that outlet (BleepingComputer, 2026-08-14).

The genuinely new defender-facing detail is the tradecraft. BleepingComputer reports the campaign confirmed independently by the Ransomware Information Sharing and Analysis Centre and by ReliaQuest, which says the actors have been deploying JSP webshells that let them steal sensitive data from victims' compromised PLM platforms (BleepingComputer, 2026-08-14). Until now this campaign was visible only as an exploited CVE at one end and a leak-site listing at the other; a webshell on the application server is the middle of the chain, and it is a durable artefact that outlives the patch. The same report notes PTC warned customers of heightened threat activity on 26 June and that CISA subsequently confirmed active exploitation and added the flaw to its Known Exploited Vulnerabilities catalog.

Triage: PLM platforms legitimately serve large volumes of engineering drawings and CAD content, so bulk document retrieval alone is weak signal. The discriminators are the requester and the path: retrieval driven by requests to a JSP endpoint absent from the vendor's shipped file manifest, and document access that does not correspond to any authenticated product-lifecycle user session.

Updaterun 2026-08-19T0410Z-intelactionscvesevidencesourcestechniquesbody

The campaign's post-exploitation tooling now has a published mechanism, and it is not a generic web shell. ReliaQuest's threat research team released a reverse-engineering analysis on 2026-08-18 of the implant deployed after exploitation of CVE-2026-12569 in PTC Windchill, stating that "This activity was highly likely conducted by the Clop extortion group" (ReliaQuest, 2026-08-18). The prior entry recorded only that JSP web shells were being deployed; what follows is the mechanism, which changes what a defender can look for.

Background. Cl0p's pattern is well documented over several years and is the reason a single flaw in a data-holding enterprise platform reliably becomes a mass-extortion wave rather than an isolated intrusion. ReliaQuest places this implant in a lineage: the group deployed the custom web shell DEWMODE after exploiting CVE-2021-27101, and LEMURLOOT after exploiting CVE-2023-34362 (ReliaQuest, 2026-08-18). BleepingComputer's account of the group's history adds the platform list those campaigns ran through (Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo and MOVEit Transfer, the last of which affected more than 2,770 organisations) along with an Oracle E-Business Suite zero-day campaign from early August 2025 (BleepingComputer, 2026-08-17). Each followed the same order: pick software that stores other people's sensitive data, exploit it at scale immediately after disclosure, deploy a purpose-built shell, then extort from the stolen data rather than from encryption.

What the implant does

The single most consequential command is a credential dump. ReliaQuest states that "A single \"S\" command to the web shell returns Windchill's directory-management and administrative credentials in plaintext" (ReliaQuest, 2026-08-18), implemented by an internal function the analysis calls gs in three steps: read Windchill's ieStructProperties.txt configuration file, decrypt the LDAP manager password from the application keystore, then iterate every stored local property decrypting the remaining encrypted values, administrative account credentials, object-storage credentials and all site administrator keys. Because LDAP credentials in most estates govern directory authentication for Active Directory, mail, VPN and whatever else federates against it, ReliaQuest's reading is that this turns one application compromise into an enterprise-wide credential compromise. A separate command exfiltrates the result.

Discovery is equally application-aware. A function fl, backed by a class the analysis names Flst1, queries Windchill's database for vault stream identifiers, filenames, storage paths and file sizes, writing the result to a file named flst.txt, a ready-made index of the repository from which the operator picks what to steal. The helper that opens that database connection uses Windchill's own internal Java classes, and this is the detection problem rather than a footnote: the implant connects through the application's MethodContext and WTConnection classes, so "its queries run under the application’s existing database identity rather than through a separately configured attacker account" (ReliaQuest, 2026-08-18). Database telemetry attributes the theft to the application's normal service account.

The third component is what makes the shell open-ended. A custom Java class loader the analysis calls Cldr takes attacker-supplied code as a Base64-encoded ZIP: "It accepts a Base64-encoded ZIP file containing compiled Java bytecode, loads it directly into memory, and executes it" (ReliaQuest, 2026-08-18). Nothing is written to disk, and the capability set is therefore not fixed at deployment; ReliaQuest notes the same channel could carry propagation tooling or file-encrypting payloads, which is a stated possibility rather than observed activity and is carried here as such.

Why ordinary monitoring misses it

Commands travel in a custom HTTP request header, X-windchill-req, rather than in a URL or a request body, and responses are GZIP-compressed so the returned data looks like ordinary compressed web content. ReliaQuest is explicit about what that costs a defender: controls inspecting only URL paths or body parameters see no command traffic at all, and controls that log headers without decompressing responses "will capture the instructions but miss the data being returned". Its conclusion is a three-part requirement, "Identifying this activity requires header logging that captures non-standard values, response decompression, and TLS inspection; without all three, coverage against this web shell's traffic is partial at best" (ReliaQuest, 2026-08-18). The analysis contrasts this with China Chopper, which it offers as the reusable-shell baseline: widely available, application-agnostic, and carrying the known patterns signature-based controls are built around. This implant carries none of them, because it behaves like the application.

Hunting and response

The hunt has three independent footholds, and the file-system one is the cheapest. ReliaQuest's own guidance is to "Review the windchill/codebase/login directory and other Windchill codebase paths on all Windchill servers for unexpected JavaServer Pages (JSP) files that could be web shells", prioritising recent modification timestamps, unfamiliar filenames, or content referencing the X-windchill-req header, MethodContext, WTConnection or WTKeyStoreUtil (ReliaQuest, 2026-08-18). In web-tier telemetry, the signal is requests to Windchill carrying a non-standard request header at all; the header name is the artifact, and an estate that logs only method, path and status will not have recorded it. In file and database telemetry, the creation of flst.txt on a Windchill server and vault-table enumeration queries that select stream identifiers and storage paths in bulk are both discoverable, as is a large outbound transfer following shortly after.

Triage: every one of these signals has a benign twin on a healthy PLM server, which is why the sequence rather than any single event is the discriminator. Windchill queries its own vault tables constantly and always under the service identity, so identity is useless as a filter and volume nearly so; what does not happen normally is a bulk enumeration of stream identifiers, filenames and sizes landing in a text file in a codebase directory, followed by an outbound transfer, followed by authentication attempts elsewhere in the estate using the LDAP manager account. Likewise, JSP files legitimately live in Windchill's codebase, a recently modified one with an unfamiliar name that references the application's keystore utility class does not.

vulnerability20 Jun 05:12Zmulti-sourceOpen finding ↗

2026-07-23 · view entry permalink →

NOTABLECVE-2026-28304 +15NATOA1

SolarWinds Serv-U 2026.3, 15 critical IDOR flaws let authenticated users escalate to root RCE on the file-transfer server (CVSS 9.1)

Serv-U 2026.3, released 2026-07-21, fixes 16 vulnerabilities (15 of them critical at CVSS 9.1) that are insecure-direct-object-reference (IDOR, CWE-639) and broken-access-control flaws in the managed-file-transfer web console rather than memory-safety bugs (SolarWinds, 2026-07-21). The consequential path is authorization: an authenticated user (in several cases needing only group- or domain-administrator scope, not full system administrator) can escalate to system administrator and achieve remote code execution as root on the underlying host, with reduced impact on Windows deployments (SolarWinds PSIRT, 2026-07-21; NCSC Switzerland, 2026-07-22). Individual flaws cover privilege escalation via configuration-path modification, arbitrary system-administrator account creation, arbitrary file read/write, account takeover through IDOR, and domain-user-group elevation to an admin group; one medium issue (CVE-2026-28315, CVSS 6.2) is a stored XSS in the admin UI usable for session hijacking. All were reported through SolarWinds' Intigriti bug-bounty program and NCSC-CH records exploitation status as unknown; heise notes Serv-U's history as a target for the Cl0p affiliate in prior MOVEit-class campaigns purely as context for why file-transfer software patch-lag is a recurring high-value target class (heise online, 2026-07-22).

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root.

SolarWinds 2026-07-21

Successful exploitation allows authenticated attackers to escalate privileges to system administrator and execute arbitrary code with root privileges via network access.

NCSC Switzerland 2026-07-22
vulnerability23 Jul 04:34Zmulti-sourceOpen finding ↗

2026-07-13 · view entry permalink →

HIGHCVE-2026-2699 +1exploitedupdatedNATOA2

Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat', day three, no patch or root cause disclosed

Progress Software has told every customer running an on-premises ShareFile Storage Zone Controller (SZC), the self-hosted IIS component that lets ShareFile's SaaS front end store files on customer-controlled storage (local filesystem, SMB, SharePoint, S3/Azure) rather than in Progress's cloud, to manually power off the Windows server hosting it, citing "a credible external security threat" first notified to customers on 2026-07-10 (BleepingComputer, 2026-07-10). Three days on, the vendor status page still lists the Storage Zone Controller service as not operational and under investigation (Progress ShareFile status, 2026-07-13), and Progress has disclosed neither a CVE, a root cause, nor a patch or safe-restart timeline; the mitigation on offer is a full shutdown rather than an update, with no fix published as of this run (heise online, 2026-07-13; SecurityWeek, 2026-07-13). heise characterises the shutdown as a precautionary measure during an ongoing investigation. Progress states it has no indication of unauthorized access to any ShareFile account or data so far. Only on-premises SZC deployments are affected; cloud-only ShareFile tenants are not.

This sits on top of a chainable pre-auth RCE that watchTowr Labs disclosed in the same component in April 2026: CVE-2026-2699 (CVSS 9.8) is a CWE-698 execution-after-redirect authentication bypass in /ConfigService/Admin.aspx, where Response.Redirect() is called with the terminate flag set to false, so the admin page body still renders and executes after the browser is told to redirect to login; CVE-2026-2701 (CVSS 9.1) chains from that access, because the storage-location validation only checks writability, letting an attacker repoint the storage repository at the IIS web root and land an ASPX web shell (watchTowr Labs, 2026-04-02). Both were fixed in Storage Zone Controller 5.12.4 (the 6.x .NET-Core branch was unaffected); watchTowr counted roughly 30,000 internet-facing SZC instances at disclosure. Progress has not said whether the current threat relates to this chain or to a separate issue.

Defender takeaway. This is the same on-prem, internet-facing, managed-file-transfer-adjacent architecture class (ShareFile, MOVEit, GoAnywhere, Cleo) that has repeatedly produced mass pre-auth exploitation, and a vendor ordering customers to pull the plug rather than patch is a strong signal to treat any exposed SZC as untrusted until Progress publishes scope. Regardless of whether the July threat proves related to CVE-2026-2699/2701, any instance still on SZC 5.x below 5.12.4 carries a known, PoC-backed pre-auth RCE and should be upgraded or taken offline now. Since Progress has confirmed no mechanism, treat the CWE-698 chain as the working hunt hypothesis.

Triage: an authenticated administrator legitimately hits /ConfigService/Admin.aspx and receives a normal authenticated session; the anomaly for the known chain is a request to that path that returns a 302 whose response body nonetheless carries the full admin-panel HTML (the execution-after-redirect behaviour) rather than the redirect being honoured, followed by configuration changes to Zone/Primary-Zone-Controller/storage-repository fields outside a change window, and, downstream, an .aspx file appearing under a StorageCenter webroot subdirectory that is not part of the vendor's shipped file set.

We have reason to believe there is a credible external security threat targeting Progress Software's ShareFile Storage Zone Controllers.

Currently, we have no indication of unauthorized access to any Progress ShareFile accounts or data.

Progress Software (via BleepingComputer)

ShareFile customers with Storage Zone Controllers are not operational at this time.

Progress ShareFile (vendor status page) 2026-07-13

The alert arrived the same day that independent honeypots began detecting active, in-the-wild attempts to exploit a critical authentication bypass vulnerability the vendor patched earlier this year in its ShareFile Storage Zone Controller software.

Honeypots run by nonprofit cybersecurity organization Shadowserver Foundation first recorded active, in-the-wild attacks attempting to exploit CVE-2026-2699 on Friday.

This smells like CL0P ransomware group activity. If you use ShareFile, be like C-3PO and 'shut them all down.'

BankInfoSecurity (ISMG) 2026-07-13

An authenticated administrative user can read arbitrary files accessible to the application's service account

Currently, we have no indication of unauthorized access to any ShareFile customer account or data

BleepingComputer 2026-07-10

Storage Zones Controller customer access is currently being restored. Recovery instructions have been provided directly to account owners.

Progress, ShareFile Status Page
Updaterun 2026-07-14T1210Z-intelcvesevidencesectorssourcestagsbody

Two developments harden the picture around Progress's emergency ShareFile Storage Zone Controller (SZC) shutdown order. First, the shutdown was not precautionary in the abstract: the alert "arrived the same day that independent honeypots began detecting active, in-the-wild attempts to exploit" the pre-auth authentication-bypass flaw CVE-2026-2699, with Shadowserver Foundation honeypots first recording those attempts on Friday 2026-07-10 (BankInfoSecurity, 2026-07-13). This moves the flaw's status from PoC-public to actively exploited. Second, defenders responded at scale, the number of internet-exposed Storage Zone Controllers fell from watchTowr's April count of about 30,000 to roughly 1,000 by 2026-07-13, evidence of widespread emergency power-downs (BankInfoSecurity, 2026-07-13). Progress restored ShareFile cloud-service access for SZC customers but continues to require the on-prem controllers themselves stay powered off pending its investigation, and still reports no evidence of unauthorized access to customer data (The Register, 2026-07-13; Progress ShareFile status, 2026-07-13).

Recorded Future analyst Allan Liska publicly assessed that the pattern "smells like CL0P ransomware group activity," pointing to Clop's long record of mass-exploiting secure file-transfer software (Accellion FTA, GoAnywhere, MOVEit, Cleo Harmony, and Oracle E-Business Suite) (BankInfoSecurity, 2026-07-13). This is a named researcher's hypothesis, not an attribution: Progress has identified no actor and disclosed no root cause.

Defender takeaway. The one-day earlier guidance (treat any exposed SZC as untrusted and keep it powered off rather than patched) is now backed by confirmed in-the-wild exploitation, so it should carry more weight, not less, for any organisation that has not yet acted. Exposure concentrates in the US and Germany, keeping this directly relevant to European on-prem file-exchange operators. The recommended state remains a full power-off of on-prem Storage Zone Controllers until Progress publishes scope; the original entry's shutdown and bounded-compromise-check actions still stand unchanged.

Updaterun 2026-07-14T2009Z-intelactionsevidencesourcestagsbody

Progress Software has confirmed the root cause behind its emergency ShareFile Storage Zone Controller (SZC) shutdown order: a high-severity path-traversal vulnerability affecting SZC versions 5.x and 6.x that lets an authenticated administrative user read arbitrary files accessible to the application's service account, write malicious content to server directories, and enumerate the filesystem layout (BleepingComputer, 2026-07-14), a CWE-22-class flaw reachable through the SZC's internet-facing IIS component. Progress has shipped patched versions 5.12.5 and 6.0.2, and a CVE identifier is reserved but will not be published for two weeks. The vendor states it has "no indication of unauthorized access to any ShareFile customer account or data," a claim that sits alongside this run's earlier finding that Shadowserver honeypots recorded in-the-wild exploitation attempts against the same component from 2026-07-10. Progress's status page confirms Storage Zone Controller customer access "is currently being restored," with recovery instructions issued directly to account owners (Progress, ShareFile Status Page, 2026-07-14), closing out the multi-day outage that began with the 2026-07-10 shutdown order.

incident13 Jul 12:45Zmulti-sourceOpen finding ↗

Earlier coverage (2)

2026-07-11NOTABLENATOA2Progress MOVEit Transfer: pre-auth SFTP DoS (CVE-2026-10699), admin table-scope bypass (CVE-2026-10698) and stored XSS (CVE-2026-11903), patched 2026.0.2France's CERT-FR/ANSSI advisory CERTFR-2026-AVI-0856 (2026-07-10) covers three newly-patched flaws in Progress MOVEit Transfer, the managed file-transfer product with a history of mass exploitation (Cl0p, 2023): CVE-2026-10699 (CVSS 7.5) is an unauthenticated SFTP-service memory leak an attacker can drive to denial of service; CVE-2026-10698 (CVSS 7.2) lets an admin-level user bypass Custom Reports table-scope restrictions to read or manipulate data outside scope; CVE-2026-11903 (CVSS 8.0) is a low-privilege stored XSS in the Ad Hoc module. No exploitation or public PoC is reported. Fixed in 2026.0.2 (and the 2025.0.8 / 2025.1.4 branch releases); Swiss/EU public-sector and finance operators running internet-facing MOVEit should prioritise the upgrade given the product's exposure profile and exploitation history.2026-05-12HIGHICO fines South Staffordshire Water £963,900, water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The RecordICO fines South Staffordshire Water £963,900 for the 2020–2022 Cl0p intrusion. Regulator-side findings call out inadequate vulnerability management, unpatched critical systems, obsolete unsupported software (Windows Server 2003) and partial SIEM coverage; 633,887 individuals' data was published on the dark web from a total holding of about 1.85 million customer records (ICO notice, 2026-05-11). Reporting by The Record adds the ZeroLogon / two-DC kill-chain detail