Follow the latest coverage, related explainers and connected technology stories.
ReliaQuest confirmed that one of its employees entered their details on a fake SSO page after being targeted with impersonation calls, giving the attacker temporary read-only access to the identity dashboard. The company said device trust controls prevented access to applications, systems, and customer data, while the ShinyHunters group claimed responsibility for the attack without final confirmation from ReliaQuest.
ReliaQuest analyzed a malicious Java tool likely linked to the Clop gang, designed specifically for PTC Windchill and FlexPLM servers. It enables the decryption of stored passwords, inventorying file repositories, and data theft after exploiting a critical remote command execution vulnerability. This comes amid an extortion campaign targeting exposed servers, while PTC began releasing fixes for the vulnerability on June 17.
Shell confirmed that it is investigating a potential security incident after the Clop group claimed to have stolen 89 gigabytes of its data, including engineering drawings and project plans. The claim is part of attacks that exploited a critical vulnerability in the PTC Windchill and FlexPLM platforms to access data belonging to several organizations.