Information Security News Blog

Cl0p affiliates targeting PTC Windchill and FlexPLM servers using CVE-2026-12569 0

Cl0p Affiliates Exploit PTC Windchill for Corporate Extortion

Corporate systems designed to securely warehouse engineering blueprints and proprietary project documentation have morphed into a lucrative extortion vector for cybercriminals. Malicious actors are actively breaching PTC Windchill and FlexPLM servers, exfiltrating invaluable intellectual...

Dependabot update cooldown workflow protecting software supply chain security 0

Dependabot and PyPI Add Supply Chain Cooldowns

GitHub and the Python Package Index (PyPI) have introduced strategic delays into dependency updates, discouraging developers from inadvertently deploying malicious packages upon initial release. Dependabot now enforces a mandatory three-day holding period by default,...

Meccha Chameleon malware infection vector via Steam Workshop maps 0

Meccha Chameleon Malware Spreads via Steam Workshop

Players of the indie game Meccha Chameleon recently encountered a dangerous security threat. Specifically, malicious actors delivered a malware dropper disguised as custom Steam Workshop maps. Furthermore, the incident escalated when attackers hijacked the...