Cl0p 랜섬웨어가 인터넷에 노출된 PTC Windchill과 FlexPLM의 취약점을 악용하고 있다.
클롭 랜섬웨어 공격자들이 인터넷에 노출된 PTC Windchill과 FlexPLM의 취약점을 이용해 데이터 강탈 캠페인을 실시하고 있다. 이들은 FlexPLM WSDL 엔드포인트의 인증 전 정보 공개와 Windchill 로그인 서블릿의 서버 측 결함을 결합해 공격을 감행하고 있다. 이에 따라 관련 시스템의 보안이 심각하게 위협받고 있다.
Cl0p ransomware actors are exploiting vulnerabilities in internet-exposed PTC Windchill and FlexPLM.
Threat actors linked to Cl0p ransomware are exploiting vulnerabilities in internet-exposed PTC Windchill and FlexPLM as part of a data extortion campaign. They are chaining an unauthenticated information disclosure in the FlexPLM WSDL endpoint with a server-side vulnerability in Windchill's login servlet. This poses a serious security risk to the affected systems.