PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug
2026-03-25T01:23:30Z•f1b205f1c159dedcf1aaa3b6fcea8c0e8a7086c52ff89b6097197d7d4605c121
FCCIran-targetingKubernetesLiteLLMPyPIRCETeamPCPbackdoorbuilt-in-vpnconsumer-routerscredential-theftemail-syncfirefoxflexplmmicrosoftoutlookprivacyptcremote-code-executionrouter-bansupply-chainvpnwindchillwiperzero-trust','mfa-bypass'
What happened
Multiple high-impact security stories: PTC warned of an imminent, critical remote-code-execution vulnerability in Windchill and FlexPLM that could be exploited for RCE; the TeamPCP group compromised the popular LiteLLM PyPI package to backdoor credential/token theft and is also deploying an Iran-targeted wiper against Kubernetes clusters; the FCC expanded its Covered List to ban new consumer routers made outside the U.S. over security concerns. The feed also reports several breaches and incidents (HackerOne employee data exposed after a Navia hack, Infinite Campus breach extortion, Mazda and a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- f1b205f1c159dedcf1aaa3b6fcea8c0e8a7086c52ff89b6097197d7d4605c121
- Enrichment time
- 2026-03-25T01:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.