PTC Windchill CVE-2026-12569 Extortion Hits Shell, Philips

Clops PTC Windchill CVE-2026-12569 Erpressung nennt Shell, Philips, GE und Fiserv als Opfer — Monate nachdem die Lücke gepatcht wurde.

The PTC Windchill CVE-2026-12569 extortion campaign run by the Clop ransomware group went fully public on August 12–13, when Clop named Shell, Philips, General Electric, Fiserv and roughly 45 other organizations on its leak site as victims of a data-theft operation running through the same PTC Windchill/FlexPLM flaw DIESEC has already covered twice this year.…

Read More

Stadler Rail Everest Ransomware: SFr10m Demand Refused

Stadler Rail Everest Ransomware: SFr10m Demand Refused

The Stadler Rail Everest ransomware incident shows what a mature extortion response looks like: the Swiss train manufacturer confirmed that the Everest group stole supplier technical data through a shared data-exchange platform and demanded roughly SFr10m (about $12.3M) — and Stadler refused outright, filing a criminal complaint instead of negotiating. What Happened Stadler Rail, an…

Read More

GodDamn Ransomware PoisonX Driver Kills EDR

GodDamn ransomware PoisonX driver

The GodDamn ransomware PoisonX driver is a Microsoft-signed kernel tool that ransomware operators use to silently kill EDR and antivirus processes before deploying encryption — and because the driver carries a legitimate Microsoft signature, standard driver-trust checks wave it straight through. What Happened Symantec disclosed on July 9, 2026 that a ransomware family called GodDamn…

Read More

Nightmare Eclipse Windows Zero-Day Trilogy

Nightmare Eclipse Windows zero-day

The Nightmare Eclipse Windows zero-day trilogy has moved from proof-of-concept code on GitHub to a confirmed, real-world intrusion: Huntress found BlueHammer, RedSun, and UnDefend deployed together in one attack chain that started with a compromised FortiGate VPN appliance. What Happened A researcher operating under the handle “Nightmare Eclipse” (also seen as “Chaotic Eclipse”) has published…

Read More