Clop built a web shell that reads the whole engineering vault — Philips, GE and Shell are all working out what it took
2026-08-19Security
CVE-2026-12569 in PTC Windchill and FlexPLM is in CISA's exploited catalogue, and ReliaQuest has pulled apart the JSP implant Clop is dropping through it. One command decrypts the LDAP manager password out of the keystore, which turns a PLM compromise into a directory compromise.