SECURITYTHE HACKER NEWS
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
New findings revealed a JavaServer Pages (JSP) web shell targeting enterprise Product Lifecycle Management (PLM) software, specifically connected to PTC Windchill and FlexPLM servers. This web shell was deployed after exploiting a critical security flaw and is characterized as an extortion platform capable of mapping sensitive data.
Mentioned