CVE-2026-12569, CVE-2026-16723
Domains:
purelogicbox[.]org
IP Addresses:
216.152.148.54, 216.152.151.204, 104.243.35.63, 5.180.41.35
Get tomorrow's brief in your inbox
Today: Cl0p affiliates are actively exploiting a CISA KEV-listed RCE in PTC Windchill/FlexPLM (CVE-2026-12569) to exfiltrate engineering data from manufacturing and aerospace targets. A critical Fastjson 1.x RCE (CVE-2026-16723) is being exploited in the wild with no patch available; enable SafeMode immediately. A malvertising campaign is assembling malware inside victims' browsers using legitimate Bun runtimes to evade detection.
Cl0p Exploiting PTC Windchill/FlexPLM for Data Extortion (CVE-2026-12569)
Cl0p (FIN11/Lace Tempest) affiliates are chaining a pre-auth info disclosure in FlexPLM's WSDL endpoint with a server-side flaw in Windchill's login servlet to achieve unauthenticated RCE. Attackers deploy hex-named JSP web shells under /Windchill/login/, enumerate file systems, stage engineering/design data, and execute double extortion. CVE-2026-12569 (CVSS 9.3) is in CISA's KEV catalog with a deadline of 2026-06-28 (already past). EPSS is 0.023 (81st percentile). Targets include manufacturing, automotive, aerospace, and retail.
216.152.148.54, 216.152.151.204, 104.243.35.63, 5.180.41.35. Search for JSP web shells under /Windchill/login/. If you cannot patch, take internet-exposed Windchill/FlexPLM instances offline. The CISA KEV deadline has passed; this is overdue.Fastjson 1.x RCE Under Active Exploitation, No Patch Available (CVE-2026-16723)
CVE-2026-16723 (CVSS 9.0) affects Fastjson versions 1.2.68 through 1.2.83 in Spring Boot fat-JAR deployments. The flaw allows unauthenticated RCE via a crafted @type value in JSON input, requiring no AutoType enablement and no classpath gadget. ThreatBook and Imperva have observed in-the-wild exploitation targeting financial services, healthcare, computing, and retail, primarily in the US. EPSS is 0.004 (34th percentile). No patched 1.x release exists.
-Dfastjson.parser.safeMode=true or switch to com.alibaba:fastjson:1.2.83_noneautotype. Inventory all direct and transitive Fastjson dependencies. Migrate to Fastjson2 (not affected). Inspect logs for suspicious @type values, nested JAR URLs, and unexpected outbound connections.DevMan RaaS: Professionalized Affiliate Portal with Structured Victim Management
PRODAFT has published a detailed analysis of the DevMan RaaS operation (tracked as Funky Mantis). Originally an affiliate for Qilin, DragonForce, Apos, and RansomHub, DevMan launched its own RaaS platform built on DragonForce's locker DNA. The portal (now v3, released January 2026) provides affiliates with payload builders, victim lifecycle management, team creation, deadline tracking, revenue fields, and integrated access brokerage with 2-3 day completion windows. DevMan has claimed 184 victims total with nearly 50 in the US, targeting technology, healthcare, financial services, and government. No new victims reported since February 2026 after a whistleblower ("GangExposed") doxxed operator identities. The group has previously claimed development of a SCADA locker designed to push ICS beyond operating parameters.
SourTrade Malvertising: Browser-Assembled Malware Using Bun Runtime
A malvertising campaign dubbed SourTrade, active since late 2024, impersonates TradingView, Solana, and Luno to target retail traders across 12 countries. The attack chain uses a novel technique: instead of delivering a complete malicious binary, the landing page uses ServiceWorkers and SharedWorkers to assemble a Windows executable inside the victim's browser. A clean Bun runtime is fetched from a secondary domain, then combined with attacker-controlled PE headers and JavaScriptCore bytecode. AES-CTR with rotating seeds ensures each assembled binary has a unique hash. The final file is delivered via Content-Disposition attachment with Mark-of-the-Web intact. The payload family is linked to the JSCEAL stealer (credential theft, keylogging, wallet theft, remote access).
purelogicbox[.]org and related indicators. Remind users to download trading/wallet software only from official vendor sites. Endpoint detection rules should flag Bun-based executables in user download directories.Insurance Phishing Evolves to Real-Time Account Hijacking
CTM360 documents a shift in insurance-sector phishing: attackers now authenticate against legitimate insurance portals in real time as victims complete login, hijacking sessions within a single browsing session rather than harvesting credentials for later use. Campaigns use sponsored Google Ads (not email/SMS) as the initial vector, with landing pages on GitHub Pages, Netlify, Wix, and other free hosting. Saudi Arabia is the primary target, with additional activity in Europe, the US, and India.
US House Extends Cybersecurity Information Sharing Act for 10 Years
The US House approved the FY2027 NDAA (216-212) with a provision reauthorizing the Cybersecurity Information Sharing Act for another decade. The law provides liability protections for private-sector threat intelligence sharing with the federal government.
Click To Pray App Leaks User Data
Click To Pray, a prayer app endorsed by the Pope with hundreds of thousands of users, has been leaking names and email addresses for months via an exposed endpoint, found by an ethical hacker.
CVE-2026-12569 (PTC Windchill)
CVSS 9.3, CISA KEV (ransomware-linked). Pre-auth RCE via chained FlexPLM info disclosure and Windchill login servlet flaw. EPSS 0.023 (81st percentile). Actively exploited by Cl0p affiliates.
CVE-2026-16723 (Alibaba Fastjson 1.x)
CVSS 9.0, no patch available. Unauthenticated RCE in Spring Boot fat-JAR deployments using Fastjson 1.2.68-1.2.83. EPSS 0.004 (34th percentile). Active exploitation observed.
-Dfastjson.parser.safeMode=true) or migrate to Fastjson2.Cl0p continues its pattern of targeting enterprise application vulnerabilities for mass data extortion, now expanding beyond file transfer appliances into PLM/engineering platforms. The Fastjson zero-day with no available patch underscores the risk of depending on libraries where the maintainer's response timeline is uncertain. Browser-based malware assembly (SourTrade) represents an evolution in delivery evasion that defenders should expect to see replicated across other campaigns.