Follow the latest coverage, related explainers and connected technology stories.
ReliaQuest analyzed a malicious Java tool likely linked to the Clop gang, designed specifically for PTC Windchill and FlexPLM servers. It enables the decryption of stored passwords, inventorying file repositories, and data theft after exploiting a critical remote command execution vulnerability. This comes amid an extortion campaign targeting exposed servers, while PTC began releasing fixes for the vulnerability on June 17.
Philips and GE confirmed that they are investigating claims by the Clop gang that it breached their systems and stole data, while Philips said a limited incident affected an internal server, was contained, and did not impact customer environments. The claims are linked to the exploitation of a critical vulnerability in the PTC Windchill and PTC FlexPLM platforms.
Shell confirmed that it is investigating a potential security incident after the Clop group claimed to have stolen 89 gigabytes of its data, including engineering drawings and project plans. The claim is part of attacks that exploited a critical vulnerability in the PTC Windchill and FlexPLM platforms to access data belonging to several organizations.