If your company runs PTC Windchill, Cl0p may already have your blueprints. Forty-plus companies. One unpatched hole in PTC's product lifecycle management software. A custom-built tool that CL0p used to crack every password on the system like a Windchill-shaped skeleton key. Shell, GE, Philips — all on the list. On the next episode of State of Cybercrime, Matt and David break down exactly how this exploitation campaign works, and what it means if your engineering data has ever touched Windchill. Plus: 1,200 rogue OpenAI agents that hacked Hugging Face on their own, the 12th Langflow bug exploited in 2026, and a JFrog flaw letting attackers forge admin access to your software supply chain.
If your company runs PTC Windchill, Cl0p may already have your blueprints. Forty-plus companies. One unpatched hole in PTC's product lifecycle management software. A custom-built tool that CL0p used to crack every password on the system like a Windchill-shaped skeleton key. Shell, GE, Philips — all on the list. On the next episode of State of Cybercrime, Matt and David break down exactly how this exploitation campaign works, and what it means if your engineering data has ever touched Windchill. Plus: 1,200 rogue OpenAI agents that hacked Hugging Face on their own, the 12th Langflow bug exploited in 2026, and a JFrog flaw letting attackers forge admin access to your software supply chain.