Security news.
Today's security brief highlights critical vulnerabilities, with Cl0p affiliates actively exploiting flaws in PTC Windchill and FlexPLM, and a researcher publishing a PoC for a GitLab RCE. Several organizations, including OnTrac and Chick-fil-A, have also reported data breaches. The ongoing discussion around AI security and its implications for cyberattacks remains a key theme.
Cl0p Affiliates Target PTC Windchill and FlexPLM with RCE
Threat actors linked to the Cl0p ransomware are exploiting unauthenticated RCE flaws in internet-exposed PTC Windchill and FlexPLM deployments for data extortion.
GitLab RCE PoC Published for Unpatched Servers
A working exploit has been released for a GitLab flaw (patched six weeks ago), allowing authenticated users to run commands as git on self-managed servers running version 18.11.3 without the update.
DevMan RaaS Portal Centralizes Operations
The DevMan ransomware-as-a-service (RaaS) scheme uses a dedicated web platform for affiliates to build payloads, manage victims, and oversee earnings, tracked as "Funky Mantis."
OnTrac Notifies Customers of Data Breach
The parcel delivery company OnTrac is informing customers about a data breach on its corporate network that may have exposed personal details.
Chick-fil-A Data Breach Affects Over 13,000 Customers
Chick-fil-A confirmed that over 13,000 customer accounts were compromised in credential stuffing attacks targeting its website and mobile app between June 17 and June 19.
Insurance Phishing Evolves to Real-Time Account Hijacking
Research by CTM360 shows that insurance-focused phishing campaigns are moving from credential harvesting to immediate account compromises.
Rockwell Patches Code Execution Flaws in Arena Simulation Software
Rockwell Automation has released patches for code execution vulnerabilities in its Arena Simulation Software that could be exploited to target industrial organizations.
Russian State-Supported Actors Target Zimbra Collaboration Suite
CISA warns that Russian state-supported cyber actors have been targeting Western government and commercial organizations using Zimbra Collaboration Suite (ZCS) software since at least July 2025.