Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest.

The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault

This article has been indexed from The Hacker News

Read the original article: