Share on social
Aug 20, 2026
Lorem ipsum

This story appeared in our weekly cybersecurity newsletter Beacon. Sign up to get weekly updates on the latest news, findings and insights, straight to your inbox every Thursday at 10AM.
Top Story This Week:
Cl0p Claims Data Theft from More than 40 Companies
Cl0p, a prolific Russian-speaking extortion group with a history of mass-exploitation campaigns, claims to have stolen data from more than 40 organizations, including an industrial manufacturer, health technology company, a fintech provider, and a restaurant payment software company. Clop is the main suspect behind a July attack exploiting a critical remote-code-execution vulnerability (CVE-2026-12569) in a widely used product lifecycle management platform, patched on June 18, with active exploitation confirmed on July 22 via JSP web-shell deployment. Claimed data varies by victim, but leaked file listings reference CAD files, software installers, databases, backups, and project files. Affected organizations have said no customer, bank, transaction, or personal data was stolen based on reviews to date, and one confirmed unauthorized access to a limited number of non-sensitive internal documents, isolating the affected systems the same day it detected the activity. (Read more in Gov Info Security)
Why it Matters
Cl0p's campaigns follow a predictable pattern Searchlight has tracked across several major mass-exploitation events since 2020: Accellion FTA, SolarWinds Serv-U, GoAnywhere MFT, MOVEit Transfer, Cleo's MFT suite, and Oracle E-Business Suite. Cl0p goes quiet for extended stretches, sometimes over a year, then resurfaces with a single zero-day or freshly patched flaw in software that many unrelated organizations happen to share, exploits it broadly before defenses catch up, and posts dozens or hundreds of victims to its leak site in one batch. The GoAnywhere campaign hit 130+ organizations in ten days; MOVEit compromised over 2,700. The PTC Windchill incident fits that mold precisely, and there's no reason to expect this is Cl0p's last swing this year.
The economics explain why this model persists. One vulnerability, found and weaponized once, can yield dozens of victims for the price of a single R&D effort, which is a far better return than chasing organizations one at a time. The asymmetry for defenders is that Cl0p sees one vulnerability in one piece of software. Every affected organization must independently discover, validate, and remediate the same exposure in order to deny the attackers before they’re successful.
What this Means for Practitioners
The priority is knowing where you're exposed before a vulnerability becomes an incident. Make sure you have a continuous view of the specialist and third-party software your organization relies on, including systems that may sit outside the usual security inventory, and can quickly identify which instances are internet-facing.
When a zero-day hits, there may be no patch available yet, so reducing unnecessary internet exposure, isolating critical systems and understanding what data and other systems they can access can provide important defensive layers while a fix is developed. Once a patch or mitigation is available, you should be able to identify affected systems immediately rather than starting with an inventory exercise.
What this Means for Security Leaders
Cl0p's campaigns demonstrate why vulnerability management alone isn't enough. An organization can have strong patching processes and still be exposed when attackers exploit a zero-day before a fix exists.
Leaders should ensure the organization can continuously answer questions such as what software we depend on, where it is exposed, and how critical that exposure is, and whether threat actors are targeting it, particularly for shared enterprise platforms that could provide attackers with access to valuable systems or data. That visibility enables teams to act preemptively, reducing unnecessary exposure before an attack occurs, rather than relying on the patch cycle to provide the first line of defense.
Discover More
How can Organizations Stop Ransomware Attacks Before They Happen
Ransomware is thought of as a single event where systems are encrypted, operations halted, ransom demanded. In reality, it's the final stage of a much longer lifecycle. In this blog Luke Donovan, Head of Threat Intelligence discusses why ransomware defense starts by closing critical gaps before an attack is launched.
Close the 24-hour Security Gap with Continuous Vulnerability Scanning
Waiting 24-hours between scans leaves organizations vulnerable to exploitation, since attackers are constantly searching for weaknesses. In this blog we discuss how real-time scaning closes that gap, helping teams find and mitigate exposures faster than attackers can exploit them.
Aggregated dashboards carry in-house collected intelligence on hundreds of groups, with continuously updated tactics, known members, and victims. Set actor-specific alerts to follow a group's activity, and use Ransomware File Explorer to search leak-site file trees for compromised files, before public disclosure. Initial Access Broker listings matching your organization's profile surface preemptively on their own dashboard.
Simply enter your company name and domain at the top of the page and enter your contact details so we can email you your organization’s Dark Web Risk Report.
Yes. Submit the form at the top of this page to receive a high-level overview of the risks that were identified using only your company name and domain. We’ll then cross-reference these details against over 475 billion recaptured datapoints in the Searchlight Cyber platform to deliver your dark web exposure report.
Searchlight's research team finds novel vulnerabilities in the enterprise software organizations depend on, and tailored alerts, matched to each supplier's asset inventory, flag when an emerging vulnerability affects the software a vendor runs, often ahead of public disclosure.
.jpg)

.png)



