Development, begins together.
Banner alanı
IFM Sensor

🚨 Giants Shaken by Cyber Attacks: Shell, GE, Philips, and PLM Software! 🚨

Süeda Asil

Corporate
  • AQUA Automation
  • art_451_942bed62993262cdbdb8eba256a7c46d.jpg

    Hackers Targeted PLM Software​


    Recently, major companies such as Shell, GE, and Philips have been targeted by the ransomware gang Clop. Attackers exploited vulnerabilities in Product Lifecycle Management (PLM) tools widely used by manufacturers. Specifically, known vulnerabilities in PTC's Windchill and FlexPLM software were utilized.

    Clop Claims Data Theft​


    Clop claimed on its dark web site to have stolen sensitive data, including diagrams, blueprints, and project drafts, from a total of 43 companies. These attacks targeted a critical input validation vulnerability (CVE-2026-12569) in internet-facing PTC Windchill and PTC FlexPLM.

    Patching Process and Delays​


    PTC began releasing patches to close this vulnerability in mid-June, urging customers to update urgently. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) also confirmed this vulnerability, mandating federal agencies to patch all Windchill and FlexPLM instances within three days.

    Enterprise Challenges and Cybersecurity Experts' Views​


    Ensar Şeker, CISO of the cybersecurity company SOCRadar, stated that there is evidence that attackers exploited these PTC environments before the public warning and remediation process could fully take effect. He also emphasized that the release of patches for complex enterprise platforms does not mean that every version can be updated immediately.

    Adam Arellano from Harness, on the other hand, stated that large organizations should patch a critical vulnerability within hours, but in practice, most are unable to do so. He added that factors such as legacy technologies, regulatory constraints, and leadership misalignment can cause even a well-known vulnerability to remain unpatched.

    Artificial Intelligence and Cyber Threats​


    Cyberattacks on manufacturing operations are not new, but artificial intelligence (AI) is increasing the speed at which attackers identify targets, find vulnerabilities, and exploit them. The connection between IT and OT systems, cloud-based tools, and remote access make systems without up-to-date cyber defenses vulnerable to attacks.

    New Access Routes to Critical Systems​


    New access routes have opened up to critical systems such as PLCs, HMIs, and other industrial control systems. CISA issued a warning in April that cyber actors are specifically targeting OT devices. Attackers are rapidly attempting to exploit exposed controllers, poorly segmented networks, or insecure remote access tools.

    A Leadership Issue​


    Arellano states that while the problem is partly technological, it is ultimately a leadership issue. He emphasized that organizations must be willing to modernize legacy environments, identify unpatchable systems, and implement compensatory controls. He added that this urgency will only increase as AI allows attackers to detect and exploit vulnerabilities faster and on a larger scale.
     
    Back
    Top