← Carolina Clear Tech

Cyber Threat Brief

2026-07-26

Listen to this brief (9:02)

Download MP3
Show Notes

Show Notes - 2026-07-26

Stories Covered

CVEs Referenced

CVE-2026-12569, CVE-2026-16723

Indicators of Compromise

Domains: purelogicbox[.]org

IP Addresses: 216.152.148.54, 216.152.151.204, 104.243.35.63, 5.180.41.35

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief -- 2026-07-26

Today: Cl0p affiliates are actively exploiting a CISA KEV-listed RCE in PTC Windchill/FlexPLM (CVE-2026-12569) to exfiltrate engineering data from manufacturing and aerospace targets. A critical Fastjson 1.x RCE (CVE-2026-16723) is being exploited in the wild with no patch available; enable SafeMode immediately. A malvertising campaign is assembling malware inside victims' browsers using legitimate Bun runtimes to evade detection.


Critical Alerts

Cl0p Exploiting PTC Windchill/FlexPLM for Data Extortion (CVE-2026-12569)

Cl0p (FIN11/Lace Tempest) affiliates are chaining a pre-auth info disclosure in FlexPLM's WSDL endpoint with a server-side flaw in Windchill's login servlet to achieve unauthenticated RCE. Attackers deploy hex-named JSP web shells under /Windchill/login/, enumerate file systems, stage engineering/design data, and execute double extortion. CVE-2026-12569 (CVSS 9.3) is in CISA's KEV catalog with a deadline of 2026-06-28 (already past). EPSS is 0.023 (81st percentile). Targets include manufacturing, automotive, aerospace, and retail.


Fastjson 1.x RCE Under Active Exploitation, No Patch Available (CVE-2026-16723)

CVE-2026-16723 (CVSS 9.0) affects Fastjson versions 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments. The flaw allows unauthenticated RCE via a crafted @type value in JSON input, requiring no AutoType enablement and no classpath gadget. ThreatBook and Imperva have observed in-the-wild exploitation targeting financial services, healthcare, computing, and retail, primarily in the US. EPSS is 0.004 (34th percentile). No patched 1.x release exists.


Ransomware & Extortion

DevMan RaaS: Professionalized Affiliate Portal with Structured Victim Management

PRODAFT has published a detailed analysis of the DevMan RaaS operation (tracked as Funky Mantis). Originally an affiliate for Qilin, DragonForce, Apos, and RansomHub, DevMan launched its own RaaS platform built on DragonForce's locker DNA. The portal (now v3, released January 2026) provides affiliates with payload builders, victim lifecycle management, team creation, deadline tracking, revenue fields, and integrated access brokerage with 2-3 day completion windows. DevMan has claimed 184 victims total with nearly 50 in the US, targeting technology, healthcare, financial services, and government. No new victims reported since February 2026 after a whistleblower ("GangExposed") doxxed operator identities. The group has previously claimed development of a SCADA locker designed to push ICS beyond operating parameters.


Business & Infrastructure Threats

SourTrade Malvertising: Browser-Assembled Malware Using Bun Runtime

A malvertising campaign dubbed SourTrade, active since late 2024, impersonates TradingView, Solana, and Luno to target retail traders across 12 countries. The attack chain uses a novel technique: instead of delivering a complete malicious binary, the landing page uses ServiceWorkers and SharedWorkers to assemble a Windows executable inside the victim's browser. A clean Bun runtime is fetched from a secondary domain, then combined with attacker-controlled PE headers and JavaScriptCore bytecode. AES-CTR with rotating seeds ensures each assembled binary has a unique hash. The final file is delivered via Content-Disposition attachment with Mark-of-the-Web intact. The payload family is linked to the JSCEAL stealer (credential theft, keylogging, wallet theft, remote access).


Insurance Phishing Evolves to Real-Time Account Hijacking

CTM360 documents a shift in insurance-sector phishing: attackers now authenticate against legitimate insurance portals in real time as victims complete login, hijacking sessions within a single browsing session rather than harvesting credentials for later use. Campaigns use sponsored Google Ads (not email/SMS) as the initial vector, with landing pages on GitHub Pages, Netlify, Wix, and other free hosting. Saudi Arabia is the primary target, with additional activity in Europe, the US, and India.


General Security News

US House Extends Cybersecurity Information Sharing Act for 10 Years

The US House approved the FY2027 NDAA (216-212) with a provision reauthorizing the Cybersecurity Information Sharing Act for another decade. The law provides liability protections for private-sector threat intelligence sharing with the federal government.


Click To Pray App Leaks User Data

Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users, has been leaking names and email addresses for months via an exposed endpoint, found by an ethical hacker.


Patch Priority


Vulnerability Disclosures

CVE-2026-12569 (PTC Windchill)

CVSS 9.3, CISA KEV (ransomware-linked). Pre-auth RCE via chained FlexPLM info disclosure and Windchill login servlet flaw. EPSS 0.023 (81st percentile). Actively exploited by Cl0p affiliates.

CVE-2026-16723 (Alibaba Fastjson 1.x)

CVSS 9.0, no patch available. Unauthenticated RCE in Spring Boot fat-JAR deployments using Fastjson 1.2.68-1.2.83. EPSS 0.004 (34th percentile). Active exploitation observed.


Trends & Context

Cl0p continues its pattern of targeting enterprise application vulnerabilities for mass data extortion, now expanding beyond file transfer appliances into PLM/engineering platforms. The Fastjson zero-day with no available patch underscores the risk of depending on libraries where the maintainer's response timeline is uncertain. Browser-based malware assembly (SourTrade) represents an evolution in delivery evasion that defenders should expect to see replicated across other campaigns.