Cl0p, tracked elsewhere as FIN11, Lace Tempest, and Graceful Spider, is exploiting unpatched PTC Windchill and FlexPLM deployments exposed to the internet, according to The Hacker News. The pattern matches Cl0p's 2023 MOVEit run and its 2024 Cleo campaign: find an edge file-transfer or PLM platform with a remotely exploitable flaw, hit every internet-facing instance before patch adoption catches up, then negotiate ransom off the stolen files rather than deployed encryptors. Windchill and FlexPLM sit inside manufacturing and engineering supply chains, holding product design data that doesn't show up in a typical breach-notification template built around names and card numbers.
The same week, BleepingComputer reported a threat actor running the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation against Thailand's Ministry of Finance, a mode that skips the human confirmation step before the agent executes commands. Cl0p's operators still script their own post-exploitation. The Thai Finance Ministry intrusion didn't need to. The distance between those two facts is now a procurement question for anyone running Windchill: patch cadence on PLM platforms has historically trailed patch cadence on Windows Server by months, and that gap is the one an unattended agent doesn't need scheduled downtime to exploit.