decrypted · 25 july 2026 · ransomware and cybercrime · vulnerabilities and patching · uk policy and law · ai and llm security

The Windchill flaw PTC patched in June, and the extortion campaign that followed

PTC patched the flaw in its Windchill product lifecycle management software back in June. Nobody outside a small circle of researchers thought much more of it until last week, when the Clop ransomware gang started emailing hundreds of employees at manufacturing, aerospace, automotive and defence firms with a blunt message: your engineering data has already left the building, and here is where to send the money.

A patch is not the same as an eviction

The vulnerability, CVE-2026-12569, is an unsafe deserialisation bug in Windchill's PDMLink component (also present in the related FlexPLM product), rated 9.3 out of 10 for severity. Deserialisation flaws are a well-worn category: the server trusts a blob of data sent to it enough to turn it back into live objects and code, without checking whether that data came from someone it should trust. PTC shipped fixes and mitigation guidance on 17 June, and CISA added the flaw to its Known Exploited Vulnerabilities list on 25 June, a sign it was already being used in the wild. PTC itself warned of "heightened threat activity" the following day.

What changed this week is the second act. Researchers at ReliaQuest and the ransomware-tracking group Ransom-ISAC confirmed that Clop had spent the intervening weeks quietly planting JSP webshells on unpatched, internet-facing Windchill and FlexPLM instances and pulling out data, before switching, from around 20 July, to mass extortion emails sent from compromised accounts. The pattern is Clop's house style: MOVEit, GoAnywhere, Accellion and Cleo all followed the same script of silent access followed by a loud demand. What is new here is the target. Windchill and FlexPLM do not hold customer records or payment card numbers, they hold product designs: the bill of materials, the CAD files, the specifications that describe how something is built. For firms in aerospace, defence and automotive, that is arguably more sensitive than a customer database.

The Secure by Design lesson

A patch fixes the hole. It does nothing about whoever climbed through it before the patch went in, which is exactly the gap Clop exploited. The deeper lesson sits earlier than that: a system holding a company's engineering intellectual property should not have been reachable from the open internet in the first place, patched or not. Secure by Design asks vendors to make the safe configuration the default one, and it asks customers to treat "is this internet-facing" as a question to answer before "is this patched". UK manufacturers and their suppliers, many of whom run Windchill precisely because it sits at the centre of product development, should be checking both this week: has the June patch actually been applied, and separately, could this system be reached without a VPN or a zero-trust gateway at all. Assume, too, that a webshell may already be sitting there from before the patch, and hunt for it rather than treating patching as the end of the job.

Also this week

A stealer with a talent scout. Varonis Threat Labs has documented Dolphin X, a commodity Windows infostealer sold on criminal forums from around $80 a month, that bundles an "AI Profiler" feature. It scores infected machines by installed software, browsing history and app usage, then sends its criminal customers a daily ranked list of which victims are worth following up on first. The stealing itself, credentials, crypto wallets, cloud tokens, SSH keys, is standard fare; the profiler is what is new, handing entry-level criminals a triage capability once reserved for bigger operations. It is a reminder that AI is lowering the cost of deciding who to attack, not just how.

A Windows zero-day with no vendor deadline. A researcher going by Nightmare Eclipse published a working proof-of-concept for a Windows User Profile Service flaw, dubbed LegacyHive, within hours of Microsoft's July Patch Tuesday. It lets a standard user load another user's registry hive and, from there, escalate privileges, and it works against fully patched systems. Microsoft says it is investigating; there is no CVE and no fix date yet, though free unofficial micropatches are available from 0patch for some versions. Until Microsoft moves, this is one for the "known gap, no vendor timeline" list.

A regulatory deadline that refuses to wait politely. The EU AI Act's high-risk obligations, covering quality management, human oversight and conformity assessment, become binding on 2 August. Brussels has provisionally agreed to push that back to December 2027, but the delay only takes effect once it is formally published, which had not happened by late July. Any UK business selling AI-enabled products or services into the EU is in scope regardless of Brexit, with penalties up to €35m or 7% of global turnover. The sensible position for UK firms this week is to prepare as though the original date holds, because legally, for now, it still does.

Sources

Questions about any of this week's stories, or want to talk through what Secure by Design means for your own systems? Get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.