ctipilot.ch
← Back to the live brief
NOTABLECVE-2026-12569exploitedupdateNATOB1incident

UPDATE — the Cl0p Windchill wave gets its first victim confirmations: Philips says a server was hit and contained, Shell says it is investigating, and a second vendor puts JSP webshells on the compromised platforms

discovered 2026-08-15 05:00 UTCrun 2026-08-15T0412Z-intel2 sourcesmulti-source

UPDATE · originally covered UPDATE — Cl0p named 44 victims on its leak site in a single batch, including a Swiss and a Dutch organisation, and one vendor assesses an earlier masked batch as possibly the Windchill campaign (2026-08-13)

yesterday's entry recorded that no organisation named in Cl0p's batch had confirmed a compromise and that leak-site information alone could not establish an access route for any listed victim. Two of them have now spoken, and a second security vendor has published the first post-exploitation detail for the campaign.

Philips, the Netherlands-headquartered health-technology group, describes the incident as an attempted cyberattack on a specific company server containing internal data, says it has since been brought under control, and states it has no impact on customer environments (NL Times, 2026-08-13). Shell told BleepingComputer it is aware of a potential incident and is working with its security teams and relevant experts to investigate (BleepingComputer, 2026-08-14). Neither statement confirms the volumes Cl0p advertises: the group claims 89 GB from Shell and 13.5 GB from Philips, figures that reach the reporting through a leak-site monitoring platform which cautions they come directly from the attackers and are not independently verified (NL Times, 2026-08-13). BleepingComputer counts Shell among 43 new victims Cl0p listed, likely targeted through internet-exposed PTC Windchill and FlexPLM instances via CVE-2026-12569, and reports General Electric named in the same batch with no comment yet from GE, Philips or PTC to that outlet (BleepingComputer, 2026-08-14).

The genuinely new defender-facing detail is the tradecraft. BleepingComputer reports the campaign confirmed independently by the Ransomware Information Sharing and Analysis Centre and by ReliaQuest, which says the actors have been deploying JSP webshells that let them steal sensitive data from victims' compromised PLM platforms (BleepingComputer, 2026-08-14). Until now this campaign was visible only as an exploited CVE at one end and a leak-site listing at the other; a webshell on the application server is the middle of the chain, and it is a durable artefact that outlives the patch. The same report notes PTC warned customers of heightened threat activity on 26 June and that CISA subsequently confirmed active exploitation and added the flaw to its Known Exploited Vulnerabilities catalog.

Triage: PLM platforms legitimately serve large volumes of engineering drawings and CAD content, so bulk document retrieval alone is weak signal. The discriminators are the requester and the path: retrieval driven by requests to a JSP endpoint absent from the vendor's shipped file manifest, and document access that does not correspond to any authenticated product-lifecycle user session.

"We are aware of a potential incident. We are working with our security teams and relevant experts to investigate," a Shell spokesperson told BleepingComputer when asked to confirm Clop's data theft claims.

BleepingComputer 2026-08-14

Philips describes the incident as “an attempted cyberattack on a specific company server containing internal data.” The healthcare technology company says the incident has since been brought under control. “This has no impact on customer environments,” a spokesperson added.

NL Times 2026-08-13

Clop's Windchill and FlexPLM attacks were also confirmed by the Ransomware Information Sharing and Analysis Centre (Ransom-ISAC), a non-profit organization dedicated to the tracking and defense against ransomware threats, and by cybersecurity company ReliaQuest, which said that the threat actors have been deploying JSP webshells that allow them to steal sensitive data from victims' compromised PLM platforms.

BleepingComputer 2026-08-14

ATT&CK mapping

2 techniques mapped from the cited reporting · MITRE ATT&CK v19.2

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

Persistence TA0003
T1505.003Server Software Component: Web Shell

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.