Daily Security Intel

Archives
Log in
Subscribe
July 26, 2026

[SecurityIntel] 26 Jul | Cl0p Exploits Exposed PTC Windchill Enterprise Software

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Sunday, July 26, 2026

INTEL CONFIDENCE  70%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Cl0p Exploits Exposed PTC Windchill Enterprise Software

CRITICAL

5

C2 IPs

0

OTX IOCs

11

ARTICLES

■ ANALYST TLDR

Today's threat landscape is dominated by active exploitation of critical unauthenticated remote code execution (RCE) vulnerabilities in enterprise software, specifically targeting Alibaba Fastjson 1.x and PTC Windchill/FlexPLM. Concurrently, sophisticated malvertising campaigns (such as SourTrade) are utilizing browser-side assembly of executables to bypass traditional network detection, while Cl0p ransomware affiliates actively target exposed PLM systems.

■ CRITICAL STORIES

CRITICAL#1

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors associated with the Cl0p ransomware group are actively exploiting unauthenticated remote code execution (RCE) flaws in internet-facing PTC Windchill and FlexPLM deployments for data extortion, threatening industrial and manufacturing supply chains.

CRITICAL#2

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Active exploitation has been detected targeting a critical unauthenticated RCE vulnerability in Alibaba's Fastjson 1.x library within Spring Boot applications, leaving organizations highly vulnerable as no official patch is currently available.

HIGH#3

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

The 'SourTrade' malvertising campaign uses browser-side JavaScript and a legitimate Bun runtime base to construct malicious Windows executables directly on the victim's machine, effectively evading network-level file detection.

HIGH#4

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

A public proof-of-concept exploit has been released for a previously patched GitLab RCE vulnerability, enabling authenticated users to execute arbitrary commands as the 'git' user on unpatched self-managed instances.

■ CVEs IDENTIFIED

[CVE-TBD]

Alibaba Fastjson 1.x — Unauthenticated Remote Code Execution in Spring Boot applications

Critical

[CVE-TBD]

GitLab Self-Managed — Remote Code Execution allowing authenticated users to run commands as git

Critical

[CVE-TBD]

PTC Windchill & FlexPLM — Unauthenticated Remote Code Execution exploited by Cl0p affiliates

Critical

[CVE-TBD]

Rockwell Automation Arena Simulation Software — Code execution vulnerabilities via malicious project files

High

■ THREAT ACTORS

Cl0p (Chubby Scorpius / FIN11 / Graceful Spider / Lace Tempest)

Ransomware Group

Exploiting unauthenticated RCE flaws in internet-exposed PTC Windchill and FlexPLM for data extortion.

ShinyHunters

Cybercrime Group / Extortionist

Leaking data used by secondary threat actors to conduct $2,000 Bitcoin sextortion email scams.

DevMan Operators

Ransomware-as-a-Service (RaaS)

Maintaining a centralized portal for payload builds, affiliate payouts, and victim management.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Used to target unpatched GitLab instances, Fastjson 1.x, and PTC Windchill/FlexPLM deployments.
T1027.004
Compile After Delivery | Observed in SourTrade and JavaScript-based malvertising campaigns assembling malware directly in browser memory.
T1204.001
User Execution: Malicious Link | Used in Steam forum ClickFix campaigns and malvertising to lure users to malicious pages.
T1566.002
Phishing: Spearphishing Link | Used in sextortion campaigns leveraging leaked ShinyHunters data.
T1486
Data Encrypted for Impact | Associated with Cl0p and DevMan ransomware operations.
T1496
Resource Hijacking | Deployment of XMRig cryptominers via compromised Steam forums.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Alibaba — Fastjson 1.x — Active exploitation of unpatched RCE in Spring Boot applications — ThreatBook / Imperva

[P1 PATCH NOW]≤24h

PTC — Windchill & FlexPLM — Unauthenticated RCE actively exploited by Cl0p ransomware affiliates — The Hacker News

[P1 PATCH NOW]≤24h

GitLab — GitLab Self-Managed — Public PoC released for authenticated RCE running commands as git — depthfirst / The Hacker News

[P2 PATCH NOW]≤72h

Rockwell Automation — Arena Simulation Software — Code execution flaws via malicious project files — SecurityWeek

■ RECOMMENDED ACTIONS TODAY

1[P1] Deploy web application firewall (WAF) rules to block malicious JSON requests targeting Alibaba Fastjson 1.x, as no official patch is currently available.
2[P1] Immediately patch all self-managed GitLab instances to version 18.11.3 or higher to mitigate the newly published authenticated RCE exploit.
3[P1] Audit and restrict internet exposure of PTC Windchill and FlexPLM deployments, and apply vendor-provided security updates to prevent Cl0p ransomware exploitation.
4[P2] Apply security patches issued by Rockwell Automation for Arena Simulation Software to prevent arbitrary code execution via malicious project files.
5[P2] Implement browser security controls and content filtering to block unauthorized execution of local runtimes (like Bun) initiated via malvertising scripts.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 27 Jul | Active scans target ESAFENET CDG weak logins Older → [SecurityIntel] 25 Jul | Autonomous AI Agents Weaponized for Enterprise Attacks
Powered by Buttondown, the easiest way to start and grow your newsletter.