ZeroHour

Search: “Clop”

2 stories in the last 30d

Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Growsnew

Black Kite reports manufacturing ransomware incidents up 40% in 2026, with new gang The Gentlemen responsible for 12% of attacks.

Black Kite's 2026 Manufacturing & Distribution Ransomware Report counted 1,183 disclosed incidents in the first seven months of 2026, a 40% year-over-year increase, led by Qilin, The Gentlemen, Akira, DragonForce, and INC Ransom. The Gentlemen, first observed in September 2025, claimed 142 manufacturing victims and was behind 12% of this year's attacks. European targeting grew 85%, with Germany (77), Italy (57), UK (43), and France (40) as top victims. The report cites the Jaguar Land Rover attack, estimated by the UK Cyber Monitoring Centre at £1.9 billion in impact with 4,000 announced job cuts, as the most economically damaging cyberattack in UK history.

SecurityWeek · 25m agoRansomware in the wild 2 sources

Cl0p Targets 40+ Organizations Through PTC Windchill Flaw

Cl0p claims over 40 organizations including Shell and Philips were breached by exploiting critical RCE CVE-2026-12569 in PTC Windchill and FlexPLM.

Cl0p claims more than 40 organizations were victimized via CVE-2026-12569 (CVSS 9.3), a critical deserialization-based remote code execution flaw in PTC Windchill PDMlink and FlexPLM, affecting releases prior to 11.0 M030; CISA added the flaw to its KEV catalog in June. ReliaQuest found the group deployed a custom web shell that maps vault data, decrypts all credentials in the Windchill keystore, and includes a Java class loader enabling arbitrary code execution, lateral movement, persistence, and large-scale data exfiltration without extra tooling. Named victims include Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Apple lens supplier Largan Precision, with stolen data ranging from one gigabyte to multiple terabytes per target. The campaign mirrors Cl0p's earlier mass-exploitation extortion operations against MOVEit, Cleo, GoAnywhere, and Oracle E-Business Suite.

Security Affairs · 27d agoRansomware in the wildCVE-2026-12569