Forum Discussion
Tenable Security Intel Brief: Clop returns with a custom Windchill web shell
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team.
This week marks one year of the Security Intel Brief. The first edition was sent on August 27, 2025.
The top story this week: the Clop extortion group is exploiting a critical PTC Windchill flaw with a custom-built web shell designed to steal engineering data and decrypt enterprise credentials.
Clop deploys a custom data-theft implant against Windchill servers →
Brief: ReliaQuest believes a purpose-built web shell, deployed after exploitation of CVE-2026-12569 (CVSS 9.3) in PTC Windchill, a product lifecycle management platform holding engineering data and product designs, is "highly likely" the work of the Clop extortion group.
Intel: The web shell, malicious code planted on the server, is equipped to steal data: credential harvesting is built in, and so are file discovery and transfer. A single "S" command reads Windchill's configuration file and decrypts the stored directory-manager, admin, and site-administrator passwords into plaintext. A built-in loader runs fresh attacker code entirely in memory, with nothing written to disk. Extortion emails match addresses on Clop's data leak site. PTC shipped its fix June 17 and CISA added the flaw to its KEV catalog June 25; extortion emails followed in mid-July.
Why it matters: The directory-manager password governs Active Directory, email, and VPN, so one decrypt command can hand an attacker credentials reaching far past the compromised server. Clop pairs mass exploitation with a fresh implant each time, the same move it ran with its DEWMODE web shell in 2021 and LEMURLOOT web shell in 2023.
Five U.S. agencies warn of AI-built scripts probing Siemens PLCs →
Brief: Five U.S. agencies issued a joint advisory warning that attackers are running AI-written scripts, dressed up to look like ordinary monitoring tools, to probe Internet-exposed programmable logic controllers (PLCs) in Siemens' S7 Series.
Intel: The NSA, CISA, FBI, DOE, and EPA say the activity spans scouting and tool-building against U.S. installations in energy, water, chemical, food, and critical-manufacturing sectors. Attackers use scanning services such as Censys and ZoomEye to find exposed or poorly segmented S7-200 through S7-1500 controllers. They then run AI-written Python scripts, built on freely available open-source code, that speak the controllers' own communication protocol. That gives read and write access to controller memory and configuration, and to the control programs that run the machinery. The agencies name no threat actor and no new vulnerability. Our team's FAQ on the advisory covers the targeted models and mitigations.
Why it matters: The controllers and their flaws were already reachable, and the open-source libraries freely available; what AI supplied was the exploitation code, sharply reducing the expertise a working ICS tool once required. Siemens told CyberScoop the advisory reflects "new techniques to exploit potential misconfigurations." The Python scripts arrive looking like software an operations team already trusts.
Medusa ransomware passes 500 victims as FBI adds two exploited flaws →
Brief: The FBI, CISA, and the Department of Health and Human Services (HHS) updated their joint #StopRansomware advisory on Medusa, reporting more than 500 victims across critical infrastructure sectors as of April 2026.
Intel: Medusa is a ransomware-as-a-service operation first seen in June 2021 that encrypts data and threatens to leak it unless victims pay. The victim count climbed from over 300 as of early 2025, hitting healthcare, schools, law firms, insurers, tech companies, and manufacturers. The refreshed advisory adds two exploited flaws: CVE-2025-10035 in Fortra GoAnywhere and CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, joining earlier flaws in ScreenConnect and Fortinet.
Why it matters: The FBI says Medusa affiliates can turn a newly announced exploit against victims inside 24 hours, and in some cases moved a week ahead of public disclosure. The group writes no zero-days of its own, so the edge comes from obtaining exploits faster than defenders can close known, fixable holes.
Talos finds a cybercrime crew running AI as its post-breach operator →
Brief: Cisco Talos discovered UAT-10147, a Chinese-speaking criminal operation that uses agentic AI, meaning AI that plans and runs multi-step tasks on its own, to automate work after breaking into web servers.
Intel: Talos assesses with moderate-to-high confidence that the financially motivated group, active since early 2026, has shifted beyond simple AI scripting help into semi-autonomous attack orchestration. Talos ties the activity to search-engine fraud and data theft. On the attackers' own servers, an unprotected folder exposed roughly 170,000 target URLs split into 17 files, alongside PentestGPT, an AI penetration-testing tool used to scan victims and launch exploits. The folder also held AI-written runbooks and Python scripts that plant the group's SPECTRE malware and backdoor code.
Why it matters: Dwell-time assumptions rest on attackers needing time for trial and error inside a compromised network, and for writing up what worked. This group handed that work to AI. The AI QA-tested the exploit before use and wrote the step-by-step runbooks its operators followed.
Stat of the week: 49
The number of Security Intel Brief newsletters sent since the first edition on August 27, 2025. Thank you to everyone who has read, forwarded, filled out a survey, or talked about the Security Intel Brief over the last year. It is because of your feedback that this newsletter is now shareable with customers and published each week in the Vulnerability Watch community.
Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.