Back to Archive
THREAT INTELLIGENCE BRIEFยทSunday, July 26, 2026ยทAI-Powered

The most urgent threat this week is an active data extortion campaign by the Cl0p ransomware group targeting internet-exposed PTC Windchill and FlexPLM systems with an unauthenticated RCE.

The most urgent threat this week is an active data extortion campaign by the Cl0p ransomware group targeting internet-exposed PTC Windchill and FlexPLM systems with an unauthenticated RCE. Additionally, a public proof-of-concept exploit has been released for a critical RCE in GitLab, significantly increasing the risk to unpatched self-managed servers. While initial reports indicated active exploitation of a critical, unpatched RCE in Fastjson (CVE-2026-16723), our threat intelligence tools show it is not on the CISA KEV list and has a low EPSS exploitation probability of 0.41%. We are also tracking a novel malvertising campaign that assembles malware directly in the user's browser.

11 articles analysed1 CVEs mentioned

Threat Categories

๐Ÿ›Vulnerabilities2
๐Ÿ”’Ransomware1
๐Ÿ“„Data Breach1
๐Ÿ’€Malware1

Article Analyses (5)

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

critical

Details

Affiliates of the Cl0p ransomware group are actively exploiting a vulnerability chain in PTC products. Attackers combine a pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint with a server-side vulnerability in the Windchill login servlet to achieve unauthenticated remote code execution.

Affected Systems

Internet-exposed PTC Windchill and FlexPLM deployments.

Potential Impact

Data extortion and theft of sensitive intellectual property, followed by potential ransomware deployment across the network.

Mitigations

Monitor vendor advisories for patches and guidance.

The Hacker NewsDraft Post

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

high
PoC

Details

Working proof-of-concept exploit code has been publicly released for a remote code execution vulnerability in GitLab. Any authenticated user who can push to a project can achieve RCE by committing a specially crafted Jupyter notebook and opening its commit diff, which triggers the exploit.

Affected Systems

Self-managed GitLab servers, version 18.11.3.

Potential Impact

Execution of arbitrary commands as the 'git' user, leading to the compromise of code repositories and theft of source code.

Mitigations

This vulnerability was patched by GitLab on June 10. All self-managed GitLab instances must be updated to a patched version immediately.

The Hacker NewsDraft Post

[CRITICAL] "Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available"

critical
CVE-2026-16723
EPSS 0.4%

Details

A critical remote code execution vulnerability exists in Alibaba's Fastjson 1.x library. In affected Spring Boot applications, an unauthenticated attacker can send a malicious JSON request to execute arbitrary code with the privileges of the Java process. There is currently no patch available for the 1.x branch.

Affected Systems

Java applications, particularly those built with Spring Boot, that use the Fastjson 1.x library for JSON processing.

Potential Impact

Execution of arbitrary code with the privileges of the Java process, potentially leading to server compromise.

Mitigations

As no patch is available, organizations should monitor vendor advisories for updates and consider implementing compensating controls.

The Hacker NewsDraft Post

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

high

Details

A novel malvertising campaign named SourTrade avoids detection by sending malware in fragments. Malicious JavaScript on fake landing pages for brands like TradingView and Solana instructs the victim's web browser to assemble the final executable in memory using a legitimate Bun runtime as a base.

Affected Systems

End-user workstations of employees who browse the web, particularly those interested in cryptocurrency or retail trading platforms.

Potential Impact

Endpoint compromise via a malicious executable assembled by the browser.

Mitigations

Advise users to be cautious of advertisements and offers related to trading platforms. Ensure browsers and security software are up-to-date.

The Hacker NewsDraft Post

ShinyHunters data leaks fuel $2,000 sextortion email scam

critical

Details

Threat actors are using email addresses and potentially old passwords exposed in previous data breaches, notably those leaked by the ShinyHunters group, to conduct large-scale sextortion campaigns. The emails threaten to release compromising material unless a $2,000 Bitcoin payment is made.

Affected Systems

Employees whose corporate or personal email addresses have been exposed in third-party data breaches.

Potential Impact

This is primarily a threat to individuals, but it can cause significant employee distress and increase the volume of security alerts. It does not indicate a direct compromise of corporate systems.

Mitigations

Advise employees to be vigilant for sextortion scams and to not engage with the attackers or make payments. Remind users to report such emails to the security team. Reinforce the importance of using unique, strong passwords for all services to limit the impact of credential reuse.

BleepingComputerDraft Post
Generated by gemini-2.5-pro